Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor

SSL VPN traffic and Virtual IP

Hi this is Payam and this is my first post here :) we have an issue and this is about SSL VPN and Virtual IPs when we connect to our network with SSL VPN we can not access Objects with their Virtual IP but that object is accessible with its local IP address. there is no same zone between SSL VPN interface and the interface that we use to access the object also the rule is from our source , from SSL VPN interface to All with service All   can anyone help to solve this issue ?


First, Welcome!

Then, does the route exist back from the objects toward the SSL VPN client IPs? Also if it's split tunnel, is the objects' subnet specified in the portal config as well as the other subnets they need to reach?


yes the route exists

the problem is we can not define VIP in the rule, only if i use any ad incoming interface then we can use VIP.


I think the problem is extintf/extip of your VIP is bound to the external interface facing the internet. SSL VPN is coming past that interface and terminated inside. So can't access the outside of the external interface. The same thing would happen when you try accessing outside interface of VIP from a local device connected to internal interface.

Why don't you use the local IP of the servers to access them via SSL VPN? That's the whole purpose of SSL VPN. VIP is for the access coming from Internet without a VPN.


same problem for me.

The problem is that I don't have the choice of the ip cause it's a FQDN own in a dns which is not in my organization.


so I use a VIP, exclude this address from my proxy.pac and use a firewall rule. It works from lan, wifi but not with vpn ssl with client.

With the portal web the url work.


How can I use this with fortinet ?


I have the same problem. Is this possible to set up with Fortigate?


Also, this is not true:

"The same thing would happen when you try accessing outside interface of VIP from a local device connected to the internal interface." - You can configure a rule for this, and it will work fine. However, I can not set the same firewall rule for SSL-VPN - why not?


Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Top Kudoed Authors