Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Installing the FortiSSL adapter for my road warriors!

Hey, I’ve a bit of a predicament on my hands. We recently installed a 300a, fortios 3 mr6 patch2, for a client and now we need to ensure that the laptop users can use the SSL VPN. Due to some fairly complex rules we’d like them to bring up a tunnel from the portal. That means they need to install the FortiSSL adapter but as the users don’t have admin rights they won’t be able to do the install themselves. To make matters more tricky the laptops are all in distant locations. They do however connect to the MPLS network during the day so we can get to them via RDP/VNC. I’m wondering if there is a way I can logon to each laptop as an administrator then install the CAB file. When they get home they can hit the portal and bring the tunnel up? Any ideas folks? I can imagine that others may of come up against this as we wouldn’t want our road warriors having admin rights now would we;-) Cheers, Greg
8 REPLIES 8
Not applicable

I was rather hoping that someone might of come up against this one and have a solution for me! I' ll create a ticket and feedback when I get a solution. Cheers, Greg
Carl_Wallmark
Valued Contributor

Hi, Download the SSL Client (.MSI) of MR7 and use a tool called PSEXEC (http://www.ss64.com/nt/psexec.html) to deploy it. Never done it myself with the SSL client, but could work =)

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C

Thanks for the advice. Unfortunately we haven' t deployed MR7 to any of our devices yet! I don' t have a dev box to play with either:-( Don' t suppose there is any way you could get the MSI to me is there? That' s probably a naughty question that I shall get slapped for;-) You say in MR7 it' s an MSI? Does that mean that when you go to activate the tunell it starts an MSI installer? Completely off topic but are you using SIP at all and if so are there any real life improvements in MR7. All my reading do far tells me that most people turn off the helpers, ALG etc and open the ports! Many thanks, Greg
Maik
New Contributor II

this MSI is to " offline" install the SSL VPN stuff on your client. This SSL VPN client can then be used by your users to dial in without navigating to the website. The SSL VPN Client from MR7 seems to work with FGT running MR5 too. If you use Client Certificate Auth, the FGT should be MR6p2. Ask your reseller for the MSI.
Carl_Wallmark
Valued Contributor

The SSL Client for MR7 works with MR6 and MR5 as well, you dont need to use a web browser anymore, it´s a " real" client. after install, go to Start->Program->Fortinet->Fortinet SSL Client. I have one customer who uses SIP, and i have turned off the SIP helper.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Not applicable

Selective - many thanks!! Your tip helped me out greatly! -Tom
Carl_Wallmark
Valued Contributor

Great ! Did you use the PSEXEC tool ?

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Not applicable

I' d hope to push the MSI via Group Policy. Will feedback on that later next week. Do we know if the user needs power user or local admin rights to run the program? I installed the MSI for a user today and then got them to test over the UK Vodafone 3G and I couldn' t get them connected. It showed a session in the SSL monitor on the FG but it wouldn' t connect them. Quite strange. I ended up changing the port to 443 in case Vodafone were blocking. That still didn' t work so I elevated the user to power user then a local administrator. Still no joy. Could be a GPO for the windows firewall messing up the connection coming back from the FG. The user will try from home so that should exclude Vodafone. Cheers, Greg
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors