Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ggntt
Contributor

SSL VPN - Split Tunnel but with some client side static routes

Hi there We have a situation where a customer is using SSL VPN to access central servers. We want to turn on split tunneling but we cant.. As VPN users need to access a number of online (external sites) services via the central site over the VPN. (online service provider has access restricted to their central site only) Is it possible to " push" static routes out to the client VPN so we can force traffic to those online services via the VPN and allow normal internet access locally ? Thanks ggntt
1 REPLY 1
Carl_Wallmark
Valued Contributor

Hi, Yes, you can push whatever routes you want, its done within in the firewall policy: In the policy where you specify: (for example) WAN1 -> ssl.root : source address: any destination address: <your static routes> You just add the address objects to the destination address, those addresses will be pushed out to the client.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors