Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tomas_p
New Contributor

how works VPN Web Mode ?

Our client is using Vasco devices with Fortigate, and after authentication to VPN device they want SSO towards their internal services – FTP, SMB, RDP, WWW, and I have difficulties designing such a scenario, as it is not clear how FortiNet Connection manager really implements functionality. I have an issue understanding how VPN SSL web-mode works for: a) HTTP internal services b) FTP internal services c) VNC connections d) RDP connections I have some questions, but i don‘t know right answers. In particular: a) From documentation, it seems that they do not use port forwarding mode, right? b) There is no agent, thus no additional IP interface is created, i.e. no IP address allocation from internal network space. c) RDP uses native RDP windows client, then does it use FortiGate device as RDP proxy server? Is that the same with VNC? d) How HTTP forwarding is working – does it uses some kind of encapculation (inside Java)? e) SMB/CIFS/FTP – it uses connection manager’s client on fortigate, is that right who knows the answers? thanks for helping
4 REPLIES 4
Tomas_p
New Contributor

So i Found in documentation, that RDP works in port forward mode. It is the same with VNS I think. Maybe somebody knows , does http works in port foward mode, too?
ede_pfau
SuperUser
SuperUser

Basically SSL VPN uses proxies for the services offered, without port translation. The client IP address range is part of the SSL VPN configuration, DHCP is not used here but client addresses are assigned to each client. And used in the policy.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
romanr
Valued Contributor

There are two ways to use Fortigate SSL VPN: Tunnel Mode: You use the SSL-VPN Client or the tunnel plugin from the SSL Portal and then receive a Tunnel IP and you configure you access policies like " ssl.root -> internal" ... Portal Mode: You log in to the Fortigate SSL VPN Portal and access your resources via Bookmarks on this portal page. Those bookmarks will lauch different apps or connect to different proxies in the Fortigate. Configuration is done via " SSLVPN" policies (Action = SSL-VPN. With portal apps/proxies the Fortigate uses its internal IP Adress to connect internal servers!! For RDP in web mode there is either a java based proxy app, that can be used to connect to a Terminal Server from just the browser. And there is a RDPNative configuration, which will launch the mstsc.exe and connect it to a port-forward! So if you need your users to have access to local resources in the RDP, you will need the RDPNative feature.. I guess there are some good examples to configure both scenarios in the Fortigate Cookbook and might answer some of your additional questions as well: http://docs.fortinet.com/cb/fortigate-cookbook.pdf best regards, Roman
Tomas_p
New Contributor

thanks for replay, especially romanr for a link to cookbook
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors