Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ps-support
New Contributor III

Restrict VIPs to SSL VPN Users (Split Tunnel)

Hello,
Is it possible to restrict VIP objects to only SSLVPN users with split tunnelling enabled? I used the following KB article but it did not seem to work. The FortiGate we are using is 7.2.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-access-a-VIP-from-a-SSL-VPN-tunnel-...

 

The VIP uses a public IP address to map to an internal IP address. 

 

10 REPLIES 10
Learnercync
New Contributor

Just a quick update. Thank you, @Christian_89, I tried what you suggested (minus the diagnostics) but it didn't work. I am going to repeat again w/ the diagnostics when time allows to see if I can isolate the issue.  

As a temporary workaround, I enabled DNS on the split tunnel and associated the public hostname w/ an internal IP address that is listed on one of the internal LAN DNS servers. It works for now and for the couple of times it hasn't, asking the user to disable IPv6 on the FortiClient network connection seems to resolve the issue. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors