Configuring SSL VPN in Fortigate

 Thanks to: https://forti1.com/

SSL VPN using web and tunnel mode

In this example, you will allow remote users to access the corporate network using an SSL VPN, connecting via web mode using a web browser, or via tunnel mode using FortiClient. Web mode allows users to access network resources, such as the AdminPC used in this example.

SSL VPN web tunnel mode 768
Configuring SSL VPN in Fortigate 6

For users connecting through tunnel mode, traffic to the Internet will also flow through FortiGate, to apply security scanning to that traffic.

During the connection phase, the FortiGate will also verify that the remote user's antivirus software is installed and up to date. This recipe is in the FortiGate Basic network collection. You can also use it as a standalone recipe.

How to Create VPN

Editing the SSL VPN portal

  1. To edit the full access SSL VPN portal, go to VPN > SSL-VPN Portals. The full access portal allows the use of tunnel mode and web mode.
  2. Under Tunnel Mode, disable Enable split tunneling for IPv4 and IPv6 traffic to ensure that all internet traffic passes through the FortiGate.
  3. Set Source IP Pools to use the default IP range SSLVPN_TUNNEL_ADDR1.
Fortinet SSL VPN tela2
Configuring SSL VPN in Fortigate 7

Under Enable Web Mode, create predefined bookmarks for any internal resources that VPN users need to access. In the example, the bookmark allows the remote user RDP access to a computer on the internal network.

SSL VPN Users
Configuring SSL VPN in Fortigate 8

Configuring SSL VPN Tunnel

  1. To configure SSL VPN tunnel, go to VPN > SSL-VPN Settings.
  2. Set Listen on the interface (s) to wan1. To avoid port conflicts, set Listen on port to 10443.
  3. Set Restrict access to allow access from any host
    Optionally set Restrict Access to Limit access to specific hosts and specify the addresses of hosts that are allowed to connect to this VPN.
  4. In the example, the Fortinet_Factory certificate is used as the server certificate. To ensure traffic is secure, you must use your own CA-signed certificate. For more information about using certificates, see Avoiding Certificate Warnings (CA-Signed Certificates).
  5. Under Tunnel Mode Client Settings, set IP Ranges to use the default IP range SSLVPN_TUNNEL-ADDR1.
Screen Shot 2020 11 17 at 11.18.03
Configuring SSL VPN in Fortigate 9

Screen Shot 2020 11 17 at 11.18.25
Configuring SSL VPN in Fortigate 10



Comentarios

Entradas populares de este blog

Guía de herramientas básicas para estudiantes: 31 apps y webs imprescindibles para ayudarte con los estudios

Comando FOR para archivos BAT

Policy Based Routing example: route one subnet via ISP A and another via ISP B