Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
handsprince
New Contributor

SSL-VPN Rounting

Dear All,

 

How can i configure SSL-VPN routing to go out to internet directly without back to company firewall?

8 REPLIES 8
norouzi
Contributor

I think your question is too general.

Please tell us more details.

 

Nihas
New Contributor

The Option is called "Split Tunneling"

if you enabled split tunneling the internet traffic will go through your ISP .

 

If you disabled split tunneling , all the traffic will pass through the fortigate only.

and you need to have one policy to access internet from ssl.root interface.

 

Thanks

Nihas [\b]
Nihas [\b]
handsprince

But i did try to enable split tunnelling but i can't access anywhere else other than my company network. Any other setting need to be tune? 

Dipen
New Contributor III

Hi

 

That's correct enabling Split Tunnel should just work..surprised that its not working.

Firstly are you using FortiClient (Thick) or SSL-VPN Client (Thin) ?

Secondly try doing a "tracert" when you connect to VPN you will be able to see if Internet traffic is also trying to pass over VPN Tunnel (Split Tunnel not working)

 

Regards

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
handsprince

Hi,

 

I am using SSL-VPN clinet (thin), i already tried enable and disable split tunnel with internet policy enable and disable. Once i disable the internet policy, traffic will stuck at tunnel no matter i enable or disable the split tunnel option.

Nihas

Hi, If you have enabled split tunnelling you don't need to create an internet policy .ie, from ssl.root to wan1/2. Second thing, Can you check whether any network overlapping is there.? Means if you have a same network (say 192.168.1.0 /24 ) ,Then there might be a chance of DNS server conflict.
Nihas [\b]
Nihas [\b]
Nihas

Hi, If you have enabled split tunnelling you don't need to create an internet policy .ie, from ssl.root to wan1/2. Second thing, Can you check whether any network overlapping is there.? Means if you have a same network (say 192.168.1.0 /24 ) ,Then there might be a chance of DNS server conflict.
Nihas [\b]
Nihas [\b]
arshadm
New Contributor

Hi,

 

As Nihas said you have to use the split tunneling option in your case.

 

But to work split tunneling it is compulsory to define the Local LAN address range in your Firewall. First create a address object which defines your local LAN in the firewall side and set it as the destination address in your VPN firewall policy.

 

Thanks,

Arshad

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors