FortiGate SSL VPN configuration
The SSL VPN configuration is comprised of these parts:
- SSL VPN portal
- SSL VPN realm
- SSL VPN settings
- Firewall policy
To configure the SSL VPN portal:
You can use the default full-access or tunnel-access profile. Ensure that under Tunnel mode, split tunneling is configured and enabled based on policy destination. You can configure additional settings as needed.
To configure the SSL VPN realm:
- Go to System > Feature Visibility.
- Enable SSL-VPN Realms.
- Click Apply.
- Under VPN > SSL-VPN Realms, click Create New.
- Enter the URL path pki-ldap-machine.
- Click OK to save.
To configure the SSL VPN settings:
- Go to System > SSL-VPN Settings.
- Input the following values:
Field
Value
Enable SSL-VPN
Enable
Listen on Interface(s)
port3
Listen on Port
10443
Server Certificate
ztna-wildcard. The Windows certificate authority issues this wildcard server certificate.
DNS Server
Specify
DNS Server #1
10.88.0.1
- Under Authentication/Portal Mapping, click Create New to create a new mapping.
- Set Users/Groups to PKI-Machine-Group.
- Set Realm to Specify.
- Select the /pki-ldap-machine realm.
- Set the portal to full-access.
- Click OK to save.
- Edit the All Other Users/Groups entry:
- Set portal to no-access.
- Click OK to save.
To configure the firewall policy:
- From Policy & Objects > Firewall Policy, click Create New to create a new policy.
- Input the following values:
Field
Value
Name
VPN-Machine
Incoming Interface
SSL-VPN tunnel interface (ssl.root)
Outgoing Interface
port2
Source
all, PKI-Machine-Group
Destination
Create an address object for the web server 10.88.0.3/32 and any other servers that must be accessed.
Schedule
always
Service
ALL
Action
ACCEPT
Log Allowed Traffic
Enabled, All Sessions
- Configure any other security profiles settings as needed.
- Click OK to save.