FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
vraev
Staff
Staff
Article Id 261095
Description

 

This article describes how to set up SSL VPN on a managed FortiGate with VPN Manager.

 

Scope

 

FortiManager v6.4 and above.

 

Solution

 

     1. Create a user group to be used for the SSL VPN authentication and add the required members (members can also be added at a later point).

 

Navigate to Policy & Objects (1) -> Object Configurations (2) -> User & Authentication (3) -> User Groups (4) -> Create New.
This example uses a local 'Firewall' (6) group, but any other application type can be used as well.

 

vraev_0-1687253492607.png

 

New users can be created later and added as members of the already existing group.

To create new users, navigate to Policy & Objects (1) -> Object Configurations (2) -> User & Authentication (3) -> User Definition (4) -> Create New.
This example uses a 'Local' (5) user, but any other applicable type can be created as well.

 

vraev_1-1687253492610.png

 

     2. Create a firewall policy with incoming interface 'sslvpn_tun_intf'. (During the installation process, FortiManager automatically resolves this default normalized interface to the respective 'ssl.<vdom>' interface of the target FortiGate VDOM).

 

Navigate to Policy & Objects (1) -> Policy Packages (2) -> [Name of PP] (3) -> Firewall Policy (4) -> Create New.

Under 'Source User Group' (9), add the group/s created in the previous step.

 

vraev_2-1687253552243.png

 

     3. If SSL VPN is disabled on the managed FortiGate, go to VPN Manager (1) -> SSL VPN (2)-> Settings (3) and select 'Create New' (4):

 

vraev_3-1687253607719.png

 

Select the managed FortiGate from the drop-down menu (1) and configure the VPN settings as required (refer to the FortiGate documentation for details on the different options):

 

vraev_4-1687253607724.png

 

Create or edit the portal mapping:

 

vraev_5-1687253607727.png

 

     4. (Optional) Create or edit SSL VPN Portals.

 

vraev_6-1687253664968.png

 

vraev_7-1687253664971.png

 

The FortiGate portal will look like this with local and SSO groups:

 

vraev_8-1687253698974.png

 

Troubleshooting:

Troubleshooting Tip: Solving the 'copy' error that occurs while installing the policy package

Technical Tip: How to fix synchronization issue in FortiManager

Troubleshooting Tip: SSL VPN Troubleshooting


Related articles:

Technical Tip: SAML SSO user group setup for a managed FortiGate

Technical Tip: Certificate Template with SCEP enrollment, using FortiAuthenticator as external CA  

Troubleshooting Tip: Common SSL VPN.

DOCS: SSL VPN. 

Technical Tip: Per-Device mapping behaviour