Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
natan
New Contributor

Split tunnel to fqdn wildcard

Hi,
Is it possible to configure in split tunnel wildcard FQDN?
I have some sites, x.abc.com, I want to set a wildcard FQDN to *.abc.com. It is possible?

7 REPLIES 7
hbac
Staff
Staff

Hi @natan,

 

Yes, it is possible. You can enable split-tunnel based on Policy Destination and put wildcard FQDN under the policy destination. 

 

Regards, 

kevinjm9
New Contributor

Hi is this same functionality possible when using an IPsec Tunnel VPN?

vbandha

Hi @kevinjm9 

Dialup IP Sec Split Tunnel does not have this functionality:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-split-tunnel-For-IPsec-VPN/ta-p/192...

'The 'Accessible Networks' Address needs to be of the subnet type '

 

Regards,

Varun

Toshi_Esumi
SuperUser
SuperUser

And, this is the KB.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Access-to-Specific-FQDN-using-Split-Tunnel...

Not sure wildcard FQDN still work in SSL VPN policy though. I would assume the same with other regular policies though. I haven't tested it yet.

 

Toshi

Toshi_Esumi
SuperUser
SuperUser

I actually have a doubt about wildcard FQDN. Because until traffic happens through the policy they wouldn't be resolved to IPs, and by that time, the split tunnel route injection to the client machine is done already. Can they be added later after the connection was established?

 

Toshi

hbac

Hi @Toshi_Esumi,

 

When the FQDN object is created, FortiGate will resolve the IPs. If the FQDN is specified as destination of SSL VPN policy, FortiGate will inject those route to VPN users once they connect. Users need to reconnect to the VPN to update the routing table. 

 

Regards, 

magnuso2
New Contributor

The IPs/subnets to route through the tunnel get pushed "statically" at the time of connecting, they don't get updated over time during the lifetime of the client's connection. So there's a chance that what the FortiGate pushes and what the client later resolves those FQDNs to doesn't align. This may also be amplified by use of wildcard FQDN - more FQNDs to resolve, more chances to miss.

https://19216811.cam/ https://1921681001.id/
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors