- On the Remote Access tab, click Configure VPN.
- Select SSL-VPN, then configure the following settings:
Enter a name for the connection.
(Optional) Enter a description for the connection.
Enter the remote gateway's IP address/hostname. You can configure multiple remote gateways by separating each entry with a semicolon. If one gateway is not available, the VPN connects to the next configured gateway.
Change the port. The default port is 443.
Enable Single Sign On (SSO) for VPN Tunnel
Enable SAML SSO for the VPN tunnel. For this feature to function, the administrator must have configured the necessary options on the Service Provider and Identity Provider. See SAML support for SSL VPN.
Select Prompt on connect or the certificate from the dropdown list.
Select Prompt on login or Save login. The Disable option is available when Prompt on connect or a certificate is configured for Client Certificate.
If you selected Save login, enter the username to save for the login.
Do not Warn Invalid Server Certificate
Select if you do not want to be warned if the server presents an invalid certificate.
Select the add icon to add a new connection.
Select a connection and then select the delete icon to delete a connection.
- Click Save to save the VPN connection.
FortiClient supports split DNS tunneling for SSL VPN portals, which allows you to specify which domains the DNS server specified by the VPN resolves, while the DNS specified locally resolves all other domains. This requires configuring split DNS support in FortiOS.
If using FortiClient on a Windows Server 2016 machine, ensure that you disable IE Enhanced Security. Otherwise, SSL VPN may not function as configured.