Hi,
can I route ssl vpn traffic through a different internet line?
For example, routing only ssl vpn through ISP2. How can I do that?
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Only create a policy to allow traffic from the SSL.root (SSL VPN interface) to wan2 (ISP2)
Check if this already solves your request
If this doesn't work you may need a policy route
Go to System > Features and Enable Advanced Routing, click apply
Go to Router > Static > Policy Routes and click Create new
Select Any for the protocol, ssl.root for incoming interface, your SSL VPN ip range as source and 0.0.0.0/0 as destination
Select Forward traffic, your wan2 (ISP2) interface as outgoing interface and enter the ISP2's gateway
Please tell me if this worked for you
Just want to point out on the firewall policy you need to SNAT SSLVPN Pool address behind the egress interface address. And you need to ensure split-tunneling is not engaged. I call this type of sslvpn access a hairpin turn.
PCNSE
NSE
StrongSwan
I haven't tested yet the vpn client.
But this configuration doesn't redirect the VPN Web Portal used by users to download the vpn client through ISP2 It goes through default gateway (ISP1). Is there any way to redirect the web vpn portal through isp2 too?
If not, I will need a dns domain name for web portal and a dns domain name for vpn ssl
Thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1717 | |
1093 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.