Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Lanwt
New Contributor II

SSL vpn and realms

Can a realm be set up with a virtual host name (so that the certificate I use for VPN will match the URL set in FortiClient) for SSL VPN?  I found the virtual host under Config vpn ssl web realm.  Is this only for web based VPN connections?

6 REPLIES 6
funkylicious
SuperUser
SuperUser

hi,

according to this document, which is quite old https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/724772/ssl-vpn-multi-realm , it should also work for SSLVPN with FortiClient, https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/724772/ssl-vpn-multi-realm#:~:text=To%20... 

"jack of all trades, master of none"
"jack of all trades, master of none"
Lanwt
New Contributor II

Okay, I have not had a chance to test but I used the CLI to create a realm with a virtual host, but the realm still shows the IP version for FortiClient.  I know the "gateway" in FortiClient needs the port as part of the URL.  The realm is set as URL Path as "test" and it says "SSL-VPN Realm can be accessed at: https://x.x.x.x:123/test" (where x.x.x.x is the IP and 123 is the port).  Virtual host is test.mydomain.com.  Do I set FortiClient gateway to test.mydomain.com:port?

funkylicious

i havent done the setup with virtual-host but try setting the FQDN and the custom port in the Customize Port. if it doesnt work try adding it to the FQDN:port

"jack of all trades, master of none"
"jack of all trades, master of none"
Lanwt
New Contributor II

Thanks Funky.  

I also wonder if the /test is needed.  but that is only a few options to try.

 

funkylicious

usually the /path is needed when using the IP in the remote gateway.

in the document, when the realm is created /qa ( https://x.x.x.x:port/qa ) and the virtual-host specified, it should translate qa.company.com to x.x.x.x/qa where the port is the mistery in this case, if the needs or not to be specified in the remote gw.

"jack of all trades, master of none"
"jack of all trades, master of none"
Lanwt
New Contributor II

Understood.  I will post the results after I have had a chance to test.

 

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors