Hi, we are facing a problem with the transition from SSL-VPN to IPSec DialUp for remote users.
The problem is that we want to maintain the functionality of the split tunnel from SSL-VPN, that means that all the subnets declared in the policies that affect the group that the user is part of, create an entry in the routing table of the client machine.
Just the subnets in the policies, and not the whole subnet(s) declared in the phase 2 of the IPSec tunnel.
Is this possibile ?
Also, some remote resources are reachable from the users only through the VPN client, because we declared the FQDN of the remote peer in the policies. To access those, should we disabling split tunneling at all ?
Currently we are working on Fortios 7.4.9, but we are planning to update to 7.6.2
Thanks
hi,
only subnets specified in the split tunneling object in IPsec Phase1 will be installed on the computer connecting to the VPN, not the ones in the firewall rules.
as for FQDN, this will not be possible as per https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-split-tunnel-For-IPsec-VPN/ta-p/192...
only subnets are possible to be selected in the split tunnel or /32 hosts, no ip ranges - https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-split-tunnel-For-IPsec-VPN/ta-p/192...
| User | Count |
|---|---|
| 2787 | |
| 1423 | |
| 812 | |
| 746 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.