Created on
05-03-2022
02:04 AM
Edited on
09-06-2024
01:32 AM
By
Anthony_E
| Description | This article describes how to configure the SSL VPN settings to utilize IP Pools addresses configured on the respective firewall policies. |
| Scope | FortiGate v7.0.6+and v7.2.0. |
| Solution |
On v6 and above, it was possible to utilize an IP pool attached to a firewall policy to access bookmarks or internal resources via SSL-VPN Web mode based on the IP that was specified on it.
For example, a firewall policy would look like the following:
config firewall policy edit 1
config firewall ippool
As of v7.0.0 and above, it is now necessary to enable a setting for FortiGate to perform source NAT based on the IP pool configured. This is due to internal code changes.
config vpn ssl settings
Note: Starting from v7.0.12, v7.2.6, v7.4.0, and above 'set web-mode-snat' option under the SSL VPN settings has been removed.
Related article: Technical Tip: IP pool and virtual IP behavior changes in FortiOS 6.4, 7.0, 7.2, and 7.4. |
Thanks for the info.
Good job!
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.