Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BusinessUser
Contributor

These Complicated VPN terms

full-access
tunnel-access
web-access
tunnel mode
web mode

 

Can anyone explain these vpn terms to me?

E.g. what is the difference between tunnel access and tunnel mode?

12 REPLIES 12
pminarik

You're overthinking it.

Of course, both tunnel-mode and web-mode can be configured for accessing anything anywhere, as long as the firewall policies, VPN profiles allow it and it is actually reachable.

 

I wrote "typically used to access internal websites", because that's one of the most usual scenarios for using web-mode, not the only one.

[ corrections always welcome ]
spoojary
Staff
Staff

Certainly! These VPN terms are commonly used in the context of remote access VPNs, and they describe different methods and levels of access to a corporate network through a VPN. Let's break down each term:

  1. Full-Access VPN:

    • A Full-Access VPN, also known as a Full-Tunnel VPN, routes all of a remote user's network traffic through the VPN tunnel. This means that when a user connects to the VPN, all their internet traffic, as well as access to resources on the corporate network, goes through the VPN connection. It provides secure access to both the internet and internal network resources.
  2. Tunnel-Access VPN:

    • Tunnel-Access is a type of access mode within a Full-Access VPN. It allows the remote user to access only specific or predefined network segments or resources within the corporate network through the VPN tunnel. It doesn't route all internet traffic through the VPN, only traffic destined for the specified corporate resources.
  3. Web-Access VPN:

    • A Web-Access VPN, also referred to as a WebVPN or SSL VPN, provides remote users with secure access to corporate web applications and services through a web browser. It doesn't require a traditional VPN client but instead relies on a web interface to access specific web-based resources. It's useful for accessing web applications while maintaining security.
  4. Tunnel Mode (VPN):

    • Tunnel Mode in the context of VPNs refers to the way in which VPN traffic is encapsulated and secured for transmission over an untrusted network, such as the internet. In this mode, the entire original IP packet is encapsulated within another packet, adding an extra layer of encryption and security. This mode is commonly used for site-to-site VPNs and Full-Access VPNs.
  5. Web Mode (VPN):

    • Web Mode, in contrast to Tunnel Mode, is a specific feature of some SSL VPNs. When using Web Mode, only web traffic is sent through the VPN tunnel, while other network traffic (e.g., non-web traffic) still uses the regular internet connection. It's suitable for scenarios where only web-based resources need to be accessed securely.

To summarize the difference between "tunnel access" and "tunnel mode":

  • "Tunnel access" refers to the type of access within a Full-Access VPN where users can access specific network segments or resources within the corporate network.
  • "Tunnel mode" is a broader term referring to the method of encapsulating and securing VPN traffic, and it's commonly used for Full-Access VPNs and site-to-site VPNs.

These terms help describe the various ways remote users can connect to a corporate network securely, depending on their access needs and the level of security required.

Siddhanth Poojary
mle2802
Staff
Staff

Hi there,

These terms relate to SSL VPN on FortiGate. There are 2 main mode of SSL VPN which are tunnel mode and web mode. While tunnel/web/full access is the name of SSL VPN portal. For more information, please refer to the following documents:

SSL VPN Tunnel mode: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/954097/ssl-vpn-tunnel-mode

SSL VPN Web mode: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/100733/ssl-vpn-web-mode

SSL VPN Portal: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/180888/web-portal-configurat...


Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors