Created on
12-17-2024
05:55 AM
Edited on
09-10-2025
03:59 AM
By
Jean-Philippe_P
Description | This article describes how to set up a local user for FortiGate to establish SSL VPN connectivity. |
Scope | FortiGate. |
Solution |
Step 1: Create a local user on the FortiGate.
Navigate below: To create users from the GUI:
Step 2: SSL VPN User Groups:
Step 3: SSL VPN portal settings:
Step 4:
Use port 443 for FortiGate GUI access, then use a different custom port for the SSL VPN listen port.
Step 5: Create a policy for SSL VPN to the WAN (Internet).
The same thing needs to be created for a policy for SSL VPN to the LAN.
Step 6: FortiClient settings.
Note: After connecting the VPN successfully, the Tunnel users will receive IPs in the range of 10.212.134.200 - 10.212.134.230. Make sure mode-cfg is enabled to receive an IP address from the SSL VPN.
To configure SSL VPN using the CLI:
Step 1: Configure the user and the user group.
config user local
config user group
Step 2: SSL VPN portal settings:
config vpn ssl web portal
Note: If the tunnel is full access, then disable the split tunnel (in that case, the internet traffic from the user will also reach the FortiGate.
Step 3: Configure SSL VPN settings:
config vpn ssl settings
Step 5:
config firewall policy edit 2
Useful commands:
get vpn ssl monitor
Useful commands for SSL VPN connection troubleshooting:
diagnose debug application fnbamd -1 diagnose debug application sslvpn -1 diagnose debug application tvc -1 diagnose debug console timestamp enable diagnose debug enable
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.