Created on
01-01-2025
11:12 PM
Edited on
10-07-2025
07:16 AM
By
Jean-Philippe_P
| Description | This article describes how to reserve SSL VPN client IP addresses without an external DHCP server. |
| Scope | FortiGate. |
| Solution |
To reserve an IP address for a specific user, it is required to assign a separate SSL VPN Portal with a unique Source IP Pool to a user. The example below shows how to reserve IP addresses for User1 and User2.
Assuming User1 and User2 are already created:
Repeat the same thing for User2, but with Source IP Pools = 192.168.100.2/32.
Results when User1 and User2 are connected.
It is important to note that there is a limited number of SSL-VPN Portals that can be created based on hardware models and firmware versions. Refer to the Maximum Value Table for 'vpn.ssl.web.portal'.
Related article: Technical Tip: SSL VPN with external DHCP Server - Fortinet Community |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.