Secure Internet browsing
This example sets up an SSL VPN tunnel that provides remote users the ability to access the Internet while traveling, and ensures that they are not subject to malware and other dangers, by using the corporate firewall to filter all of their Internet traffic. Essentially, the remote user will connect to the corporate FortiGate unit to surf the Internet.
Using SSL VPN and FortiClient SSL VPN software, you create a means to use the corporate FortiGate to browse the Internet safely.
Creating an SSL VPN IP pool and SSL VPN web portal
- Go to VPN > SSL-VPN Portals and select tunnel-access.
- Disable Split Tunneling.
- For Source IP Pools select SSLVPN_TUNNEL_ADDR1.
- Select OK.
Creating the SSL VPN user and user group
- Create the SSL VPN user and add the user to a user group configured for SSL VPN use.
- Go to User & Device > User Definition and select Create New to add the user:
- Select OK.
- Go to User & Device > User Groups and select Create New to add
twhite
to a group calledSSL VPN
: - Move twhite to the Members list.
- Select OK.
User Name |
twhite |
Password |
password |
Name |
SSL VPN |
Type |
Firewall |
Creating a static route for the remote SSL VPN user
Create a static route to direct traffic destined for tunnel users to the SSL VPN tunnel.
- Go to Network > Static Routes and select Create New to add the static route.
- Select OK.
Destination IP/Mask |
10.212.134.0/255.255.255.0 |
Device |
ssl.root |
|
The Destination IP/Mask matches the network address of the remote SSL VPN user. |
Creating security policies
Create an SSL VPN security policy with SSL VPN user authentication to allow SSL VPN traffic to enter the FortiGate unit.
- Go to Policy & Objects > IPv4 Policy and select Create New.
- Add an SSL VPN security policy as below, and click OK.
- Select OK.
Incoming Interface |
ssl.root |
Outgoing Interface |
internal |
Source Address |
all |
Source User Group |
SSL VPN |
Destination |
all |
Configuring authentication rules
- Go to VPN > SSL-VPN Settings and select Create New under Authentication/Portal Mapping.
- Add an authentication rule for the remote user:
- Select OK and Apply.
Users/Groups |
Tunnel |
Portal |
tunnel-access |
Results
Using the FortiClient SSLVPN application, access the VPN using the address https://172.20.120.136:443/
and log in as twhite
. Once connected, you can browse the Internet.
From the FortiGate GUI, go to Monitor > SSL-VPN Monitor to view the list of users connected using SSL VPN. The Subsession entry indicates the split tunnel which redirects to the Internet.