Skip to main content
Shadi
Staff
Staff
May 23, 2023

Technical Tip: Optional security considerations for FortiOS SSL VPN access

  • May 23, 2023
  • 0 replies
  • 1587 views
Description

This article describes challenges associated with securing SSL VPN access for a distributed user base. It is commonplace that users originate from IP addresses unknown to the Administrator. To help Administrators mitigate the risks unique to their environment, the following comprehensive list of references has been compiled.

Scope All versions of FortiGate.
Solution

Authenticating servers:

 

For networks with many users, integrate the user configuration with existing authentication servers through LDAP, RADIUS, or FortiAuthenticator.

By integrating with existing authentication servers such as Windows AD, there is a lower chance of making mistakes when configuring local users and user groups. Administration effort is also reduced.

 

Articles:

https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/490351/ssl-vpn-authentication

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-restrict-SSL-VPN-user-to-tunnel-mode-and/ta-p/218957

 

MFA:

 

General information: https://docs.fortinet.com/multi-factor-authentication/7.2.

 

FortiToken (requires FortiToken license purchase) https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/458581/ssl-vpn-with-fortitoken-two-factor-authentication.

 

Mail-Free: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Forticlient-SSLVPN-using-email-two-factor/ta-p/194023.

 

SMS: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SMS-Two-Factor-Authentication-with-3rd/ta-p/196455.

              

Certificates: https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/266506/ssl-vpn-with-certificate-authentication  https://community.fortinet.com/t5/FortiClient/Technical-Tip-SSL-VPN-with-client-authentication-using/ta-p/191864.

 

Using a non-factory SSL certificate: https://docs.fortinet.com/document/fortigate/6.2.12/cookbook/825073/procure-and-import-a-signed-ssl-certificate.

 

Limit access to specific hosts:

 

User source IP, DDNS: https://community.fortinet.com/t5/FortiGate/Technical-Tip-set-source-address-in-SSL-VPN-settings/ta-p/194231.

 

Geolocation: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restricting-SSL-VPN-connectivity-from-certain/ta-p/191997.

 

Negate access limits for specific hosts: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-SSL-VPN-Connection-from-a-certain/ta-p/206883.

              

Local in policies to deny by geoIP or addresses:

- https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restricting-Allowing-access-to-the-FortiGate-SSL/ta-p/222845.

- https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restrict-unauthorized-access-on-the-SSL-VPN/ta-p/220413.

              

Using host check software (using FortiClient 7.0.3 or higher):

- https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/32970/configuring-os-and-host-check.

- https://community.fortinet.com/t5/FortiGate/Technical-Tip-Details-about-host-check-list-and-host-check/ta-p/197114.

- https://community.fortinet.com/t5/FortiGate/Technical-Tip-Adding-custom-host-check-definitions-for-FortiGate/ta-p/189459.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enabling-periodic-host-check/ta-p/189806.

 

Web portal (if not used):

 

Most attack attempts use the web portal to try to login, which generates VPN event logs for this attempt.

If web portal is not being utilized, prevent the login page from appearing.

 

Delete login page from the replacement messages settings: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-prevent-the-SSL-VPN-web-login-portal-from/ta-p/215905.

 

Web portal or Forticlient (in use):

 

Use realms: https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/724772/ssl-vpn-multi-realm.

 

Control SSL version and cipher suite: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-control-the-SSL-version-and-cipher-suite/ta-p/191437.

 

MAC address check: https://community.fortinet.com/t5/FortiGate/Technical-Tip-MAC-Address-check-on-SSL-VPN-connections/ta-p/194337.

 

Limit the count of failed login attempts and ban the user: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-limit-SSL-VPN-login-attempts-and-block/ta-p/194229?externalID=FD48714.

 

Migrating from SSL VPN to ZTNA:

 

ZTNA can be used to replace VPN-based teleworking solutions to enhance the user experience and to increase security.

 

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/78050/migrating-from-ssl-vpn-to-ztna

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!