Yall smart people know how to only allow split tunnel on a remote worker for a specific subnet? to let’s say 192.168.13.x. All other traffic (including internet ) go through the tunnel?
Hi! Go to VPN -> SSL-VPN portals. There you can define tunnel mode. Select "Enabled Based on Policy Destination". Or in the cli as showed below.
config vpn ssl web portal
edit tunnel-access
set split-tunneling enable
end
Check this manual: Link
HI,
For Dialup IPSEC you need to use below option under phase1 settings:
config vpn ipsec phase1-interface
edit "Dialup_IPsec"
ipv4-split-include "subnet" ------->define your split range and use that address object here.
So the traffic which matched this split range will only be routed towards FortiGate over Dialup tunnel.
other traffic will exit from your local internet adapter.
Thank you.
Regards,
Prince
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.