FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Shashwati
Staff
Staff
Article Id 285987
Description This article describes how to configure split tunnel for SSL VPN using address override
Scope FortiGate 6.X and 7.X
Solution
  1. Configure the SSL VPN user group.

 

5.PNG

 

  1. Configure SSL VPN Settings

1.PNG

 

2.PNG

 

  1. Configure the allowed subnet for the SSL VPN users.

10.PNG

 

  1. Configure the SSL VPN Portal using a Routing Address Override. The subnet allowed on this address override will only be accessible for SSL VPN users.

3.PNG

 

  1. Configure a Firewall policy:

4.PNG

 

  1. Configure the interface subnet as follows:

9.PNG

 

  1. The user will able to connect to the SSL VPN:

7.PNG

 

  1. The connected user will only be able to access the allowed subnet 192.168.1.0/24.

 

12.PNG

 

An example of a route print from the user's machine:

 

14.PNG

 

Note: User Internet traffic will not be forwarded to the tunnel. 

 

Related article:

Technical Tip: Enabling split tunnel feature for SSL VPN.

Contributors