FortiOS v3.0 MR7 SSL VPN User Guide
60
01-30007-0348-20080718
SSL VPN virtual interface (ssl.root)
Configuring a FortiGate SSL VPN
Figure 21: Firewall policy list
To avoid overlap with other firewall policies, add a DENY policy below the SSL
VPN policies (the source is the SSL VPN tunnel IP range). See
Configuring
firewall policies
for more information.
SSL VPN virtual interface (ssl.root)
Configuration of the SSL VPN tunnel service involves a virtual interface,
ssl.<vdom_name>, which functions much like an ipsec-virtual interface. In non-
vdom implementations, this appears as ssl.root. The ssl.root interface appears in
the firewall policy interface lists and static route interface lists. The ssl-root
interface allows remote user access to additional networks. For example, the
interface facilitates the remote user´s ability to browse the Internet using the
FortiGate unit.
The SSL VPN tunnel-mode access requires the following firewall policies:
•
External > Internal, with the action set to SSL, with an SSL user group
•
ssl.root > Internal, with the action set to Accept
•
Internal > ssl.root, with the action set to Accept
This also requires a new static route and should appear as follows:
•
Destination network - <ssl tunnel mode assigned range> interface ssl.root
If you are configuring Internet access through an SSL VPN tunnel, the following
configuration must be added:
•
ssl.root > External, with the action set to Accept, with NAT enabled
Summary of Contents for FORTIOS V3.0 MR7
Page 1: ...www fortinet com FortiOS v3 0 MR7 SSL VPN User Guide U S E R G U I D E...
Page 6: ...FortiOS v3 0 MR7 SSL VPN User Guide 6 01 30007 0348 20080718 Contents...
Page 88: ...FortiOS v3 0 MR7 SSL VPN User Guide 88 01 30007 0348 20080718 Index...
Page 89: ...www fortinet com...
Page 90: ...www fortinet com...