Fortinet white logo
Fortinet white logo

Administration Guide

Agentless VPN portal configurations

Agentless VPN portal configurations

An Agentless VPN portal enables users to access network resources through a secure channel using a web browser. System administrators can configure login privileges and available network resources for users. The portal configuration determines what displays for users logged in to the portal. Both system administrators and users can customize the Agentless VPN portal.

The following predefined, default Agentless VPN portal configurations are available with specific settings for Agentless VPN:

  • full-access: Agentless VPN is enabled.
  • tunnel-access: Agentless VPN is disabled.
  • web-access: Agentless VPN is enabled.

Custom Agentless VPN portals can also be configured.

To configure a custom Agentless VPN portal:
  1. Go to VPN > Agentless VPN Portals and click Create New.

  2. Configure the following settings as needed:

    GUI option

    Description

    Name

    Enter the portal name.

    Limit Users to One Agentless VPN Connection at a Time

    This option is disabled by default. When enabled, once a user logs in to the portal, they cannot go to another system and log in with the same credentials again.

    Web Mode

    This option enables or disables Agentless VPN. By default, this option is enabled for new Agentless VPN portals and hidden from the GUI. The option is visible in the GUI after being disabled using the CLI.

    Portal Message

    Enter a message that appears at the top of the web portal screen (default = Agentless VPN Portal).

    Theme

    Select a color theme from the dropdown.

    Default protocol

    Select the default protocol to be visible under Quick Connection.

    Show Session Information

    Enable to display session information in the top banner of the Agentless portal (username, amount of time logged in, and traffic statistics).

    Show Connection Launcher

    Enable to display the Quick Connection button.

    Show Login History

    Enable to display the user's login history (History).

    User Bookmarks

    Enable to allow users to add their own bookmarks (New Bookmark).

    Predefined Bookmarks

    Use the table to create and edit predefined bookmarks. See To create a predefined administrator bookmark in FortiOS: for more details.

    Rewrite Content IP/UI/

    Enable contents rewrite for URIs containing IP-address/ui/.

    RDP/VNC clipboard

    Enable to support RDP/VPC clipboard functionality.

    FortiClient Download

    Enable this option to display the Download FortiClient button.

    Download Method

    Select either Direct or Agentless VPN Proxy as the method to download FortiClient.

    Customize Download Location

    Enable to configure a custom download location for Windows or Mac.

  3. Click OK.

Tooltip

By default, the browser's language preference is automatically detected and used by the Agentless VPN web portal login page. The system language can still be used by changing the settings on the Agentless VPN Settings page of the GUI, or disabling browser-language detection in the CLI. See Showing the Agentless VPN web portal login page in the browser's language for more details.

Agentless VPN portal configurations

Agentless VPN portal configurations

An Agentless VPN portal enables users to access network resources through a secure channel using a web browser. System administrators can configure login privileges and available network resources for users. The portal configuration determines what displays for users logged in to the portal. Both system administrators and users can customize the Agentless VPN portal.

The following predefined, default Agentless VPN portal configurations are available with specific settings for Agentless VPN:

  • full-access: Agentless VPN is enabled.
  • tunnel-access: Agentless VPN is disabled.
  • web-access: Agentless VPN is enabled.

Custom Agentless VPN portals can also be configured.

To configure a custom Agentless VPN portal:
  1. Go to VPN > Agentless VPN Portals and click Create New.

  2. Configure the following settings as needed:

    GUI option

    Description

    Name

    Enter the portal name.

    Limit Users to One Agentless VPN Connection at a Time

    This option is disabled by default. When enabled, once a user logs in to the portal, they cannot go to another system and log in with the same credentials again.

    Web Mode

    This option enables or disables Agentless VPN. By default, this option is enabled for new Agentless VPN portals and hidden from the GUI. The option is visible in the GUI after being disabled using the CLI.

    Portal Message

    Enter a message that appears at the top of the web portal screen (default = Agentless VPN Portal).

    Theme

    Select a color theme from the dropdown.

    Default protocol

    Select the default protocol to be visible under Quick Connection.

    Show Session Information

    Enable to display session information in the top banner of the Agentless portal (username, amount of time logged in, and traffic statistics).

    Show Connection Launcher

    Enable to display the Quick Connection button.

    Show Login History

    Enable to display the user's login history (History).

    User Bookmarks

    Enable to allow users to add their own bookmarks (New Bookmark).

    Predefined Bookmarks

    Use the table to create and edit predefined bookmarks. See To create a predefined administrator bookmark in FortiOS: for more details.

    Rewrite Content IP/UI/

    Enable contents rewrite for URIs containing IP-address/ui/.

    RDP/VNC clipboard

    Enable to support RDP/VPC clipboard functionality.

    FortiClient Download

    Enable this option to display the Download FortiClient button.

    Download Method

    Select either Direct or Agentless VPN Proxy as the method to download FortiClient.

    Customize Download Location

    Enable to configure a custom download location for Windows or Mac.

  3. Click OK.

Tooltip

By default, the browser's language preference is automatically detected and used by the Agentless VPN web portal login page. The system language can still be used by changing the settings on the Agentless VPN Settings page of the GUI, or disabling browser-language detection in the CLI. See Showing the Agentless VPN web portal login page in the browser's language for more details.