Created on
09-17-2023
09:47 PM
Edited on
08-14-2025
06:52 AM
By
Anthony_E
| Description | This article describes how to reach an SSL VPN client PC from the internal network. |
| Scope | FortiGate v6.X and v7.X. |
| Solution |
To reach a connected SSL VPN client from the internal network behind FortiGate, a new firewall policy is required. In the FortiGate GUI, go to Policy & Objects -> Firewall Policy -> +Create New. The 'Incoming interface' of the new policy will be the internal interface, and the 'Outgoing interface' will be ssl.root. A source address of 'all' and a destination address of 'all' can be used, but the internal subnet (for the source address) and the SSL VPN tunnel IP range (for the destination address) can be used to limit the access. Ensure that 'NAT' is disabled:
Note: Starting from v7.6.3, the SSL VPN tunnel mode will no longer be supported, and SSL VPN web mode will be called 'Agentless VPN'. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.