This article describes how to set up SSL VPN on a managed FortiGate with VPN Manager.
FortiManager v6.4 and above.
1. Create a user group to be used for the SSL VPN authentication and add the required members (members can also be added at a later point).
Navigate to Policy & Objects (1) -> Object Configurations (2) -> User & Authentication (3) -> User Groups (4) -> Create New.
This example uses a local 'Firewall' (6) group, but any other application type can be used as well.
New users can be created later and added as members of the already existing group.
To create new users, navigate to Policy & Objects (1) -> Object Configurations (2) -> User & Authentication (3) -> User Definition (4) -> Create New.
This example uses a 'Local' (5) user, but any other applicable type can be created as well.
2. Create a firewall policy with incoming interface 'sslvpn_tun_intf'. (During the installation process, FortiManager automatically resolves this default normalized interface to the respective 'ssl.<vdom>' interface of the target FortiGate VDOM).
Navigate to Policy & Objects (1) -> Policy Packages (2) -> [Name of PP] (3) -> Firewall Policy (4) -> Create New.
Under 'Source User Group' (9), add the group/s created in the previous step.
3. If SSL VPN is disabled on the managed FortiGate, go to VPN Manager (1) -> SSL VPN (2)-> Settings (3) and select 'Create New' (4):
Select the managed FortiGate from the drop-down menu (1) and configure the VPN settings as required (refer to the FortiGate documentation for details on the different options):
Create or edit the portal mapping:
4. (Optional) Create or edit SSL VPN Portals.
The FortiGate portal will look like this with local and SSO groups:
Troubleshooting:
Troubleshooting Tip: Solving the 'copy' error that occurs while installing the policy package
Technical Tip: How to fix synchronization issue in FortiManager
Troubleshooting Tip: SSL VPN Troubleshooting
Related articles:
Technical Tip: SAML SSO user group setup for a managed FortiGate
Technical Tip: Certificate Template with SCEP enrollment, using FortiAuthenticator as external CA
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.