FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nradia_FTNT
Staff
Staff
Article Id 274095
Description This article describes how to reach an SSL VPN client PC from the internal network.
Scope FortiGate v6.X and v7.X.
Solution

To reach a connected SSL VPN client from the internal network behind FortiGate, a new firewall policy is required.

In the FortiGate GUI, go to Policy & Objects -> Firewall Policy -> +Create New. The 'Incoming interface' of the new policy will be the internal interface, and the 'Outgoing interface' will be ssl.root. A source address of 'all' and a destination address of 'all' can be used, but the internal subnet (for the source address) and the SSL VPN tunnel IP range (for the destination address) can be used to limit the access.  Ensure that 'NAT' is disabled:

 

image.png

 

Note:

Starting from v7.6.3, the SSL VPN tunnel mode will no longer be supported, and SSL VPN web mode will be called 'Agentless VPN'.