Fortinet black logo

Cookbook

Configuring the SSL-VPN

Copy Link
Copy Doc ID 502fabff-dbf1-11ea-96b9-00505692583a:687430
Download PDF

Configuring the SSL-VPN

To configure the SSL-VPN:
  1. On the FortiGate, go to VPN > SSL-VPN Portals, and edit the full-access portal.
  2. Disable Split Tunneling.

  3. Go to VPN > SSL-VPN Settings.
  4. Under Connection Settings set Listen on Port to 10443.

    Under Tunnel Mode Client Settings, select Specify custom IP ranges and set it to SSLVPN_TUNNEL_ADDR1.

    Under Authentication/Portal Mapping, select Create New.

  5. Assign the LDAPgroup user group to the full-access portal, and assign All Other Users/Groups to the desired portal. Select Apply.
  6. Select the prompt at the top of the screen to create a new SSL-VPN policy, including the LDAPgroup, as shown.

Configuring the SSL-VPN

To configure the SSL-VPN:
  1. On the FortiGate, go to VPN > SSL-VPN Portals, and edit the full-access portal.
  2. Disable Split Tunneling.

  3. Go to VPN > SSL-VPN Settings.
  4. Under Connection Settings set Listen on Port to 10443.

    Under Tunnel Mode Client Settings, select Specify custom IP ranges and set it to SSLVPN_TUNNEL_ADDR1.

    Under Authentication/Portal Mapping, select Create New.

  5. Assign the LDAPgroup user group to the full-access portal, and assign All Other Users/Groups to the desired portal. Select Apply.
  6. Select the prompt at the top of the screen to create a new SSL-VPN policy, including the LDAPgroup, as shown.