| Description | This article describes how to configure a split tunnel to bypass FortiSASE using the local application and verify in endpoint. |
| Scope | FortiSASE, FortiClient. |
| Solution |
Local application that has to be bypassed can be specified by their name, full path, or the directory where it is installed. Environment variables (e.g. %programfiles%, %appdata% ) can be used in file and directory paths.
For the illustration, 'QuickAssist.exe' is bypassed. Note that it is not specific to quick assist (has dependency on other apps) and can be followed for any local applications.
File path can be identified by opening Task Manager and clicking on Open File Location. Copy the path.
Run netstat -naob from the command line. The output would show the interface from which connection is established/listening. In this case it was taking a physical gateway.
Confirm the config is updated in the registry for FortiClient (Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FortiClient\Sslvpn\Tunnels\Secure Internet Access\Traffic Control\apps).
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.