Dear All,
How can i configure SSL-VPN routing to go out to internet directly without back to company firewall?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I think your question is too general.
Please tell us more details.
The Option is called "Split Tunneling"
if you enabled split tunneling the internet traffic will go through your ISP .
If you disabled split tunneling , all the traffic will pass through the fortigate only.
and you need to have one policy to access internet from ssl.root interface.
Thanks
But i did try to enable split tunnelling but i can't access anywhere else other than my company network. Any other setting need to be tune?
Hi
That's correct enabling Split Tunnel should just work..surprised that its not working.
Firstly are you using FortiClient (Thick) or SSL-VPN Client (Thin) ?
Secondly try doing a "tracert" when you connect to VPN you will be able to see if Internet traffic is also trying to pass over VPN Tunnel (Split Tunnel not working)
Regards
Ahead of the Threat. FCNSA v5 / FCNSP v5
Fortigate 1000C / 1000D / 1500D
Hi,
I am using SSL-VPN clinet (thin), i already tried enable and disable split tunnel with internet policy enable and disable. Once i disable the internet policy, traffic will stuck at tunnel no matter i enable or disable the split tunnel option.
Hi,
As Nihas said you have to use the split tunneling option in your case.
But to work split tunneling it is compulsory to define the Local LAN address range in your Firewall. First create a address object which defines your local LAN in the firewall side and set it as the destination address in your VPN firewall policy.
Thanks,
Arshad
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.