Thx. With FortiOS 6 and 7, it should be much easier if used to work with
CLI. Can use the exempt list or GEO list. But with FortiOS 5, must use
the way mentioned above to exyclude for SSL-VPN. Normal block in IP
policy wont work.
Despite 5 years later, a Big thanks to you! With Fortigate 5.6, there is
no exempt list yet availabe from an address group which was introduced
in Fortios 6 and 7.