HomeSecurityHow to Configure SSL VPN on FortiGate Firewall

How to Configure SSL VPN on FortiGate Firewall

In this article, we see how to configure SSL VPN on FortiGate 60F firewall. FortiGate firewalls are custom-made security processers that permit the manufacturing’s prime threat security. A lot of devices are designed to identify issues rapidly and intuitively.

We are going to set up an SSL VPN from Windows to the FortiGate Firewall. You can Install FortiClient on Windows, and then you can configure the firewall for FortiClient. We have two kinds of SSL VPNs: web-based mode and tunnel mode. The web-based mode does not need any agents, and you must be able to reach the server from Windows. Tunnel mode is via FortiClient. The goal of this article is to provide connectivity from home to office using FortiGate F60 Firewall SSL VPN.

Configure SSL VPN on FortiGate Firewall

Work Environment

FortiGate 60F
Version 7.4.2

Establish SSL VPN Connection from External Client to FortiGate

Configure an SSL VPN from a client outside the network to FortiGate inside the network so that outside clients can access the inside network.
You need to install the VPN client application named FortiClient on the external client. You can download the FortiClient from the FortiClient download page.

SSL VPN diagram

Here, as an example, interfaces are shown in the image below.

Fortigate firewall interface

How to Create Address Object for SSL-VPN Client

To create a new address object as an address pool to issue IP addresses to SSL-VPN clients. Expand Policy & Objects settings and click on addresses. Select the Create New tab and then address.

Firewall Fortigate addresses

Enter an address name
Type: IP Rang
IP Range: 192.168.2.241-192.168.2.248 (to provide IP addresses to SSL-VPN clients).
Click ok

Create new address in Fortigate firewall

Create one more new address for your office’s internal vlan.
Name: VPN-Local-Desk
Type: Subnet
IP/Netmask: 192.168.2.0/24
Click ok

Create new address in Fortigate

Now you can see that two addresses were successfully created.

Fortigate firewall address

Create New User for FortiGate SSL-VPN

Expand Users & Authentication settings, click on User Definition, and then click on + Create New.

Fortigate firewall user definition

Choose the local user, and then click next.

Firewall users/groups creation wizard

Enter your username and password, and then click next.

Fortigate login credentials

Choose Next

Fortigate two-factor authentication

Click submit

User definition FortiGate firewall

An SSL VPN user was successfully created.

Fortigate firewall user definition

Create New User Group for FortiGate SSL-VPN

Select user group settings and then click on + create a new tab.

Firewall 60F user groups

Type a new user group name (SSL-VPN).
Click on the + button next to members, and then select the user we created earlier.

Create new group firewall 60F

Select ok

Fortigate firewall user groups

After creating a user group,.

FortiGate firewall 60F user groups

How to Create an SSL-VPN Portal in FortiGate Firewall

Expand VPN settings, and then click on SSL-VPN Portals.
Click on the + Create New tab to create a new SSL-VPN portal.

Firewall 60F SSL-VPN Portals

Create an SSL-VPN Portal in Tunnel mode.
Choose enabled based on policy destination
To select source IP pools, click on the + button and then select “SSL-VPN Users,” the one we created in the address. Click ok

Create SSL VPN Portals

SSL VPN Portal was successfully created.

SSL-VPN portals Fortigate

Configure SSL VPN on FortiGate 60F Firewall

Click on SSL-VPN Settings under VPN.
Listen on interfaces. Click on the + icon and then select your interfaces (wan1 or wan2). Please keep in mind that these interfaces should have public IP addresses.
I am testing the SSL VPN connection in my home lab; that’s why I am using a private IP address.
Listen on Port: 10443
Server Certificate: Fortinet_Factory
IP Range: Click on the + icon to add VPN users (SSLVPN-Users).

Authentication/Portal Mapping

Click on All Other Users/Groups, and then click on Edit.

Configure SSL VPN on FortiGate Firewall

From the portal, choose full-access, and then click OK.

Edit default authentication/portal mapping

Select + Create New.

Setup SSL VPN on Fortigate

Users/Groups: Choose a group (SSL-VPN).
Portal: Choose full-access and then click OK.

New authentication/portal mapping

Click Apply

Fortigate firewall SSL VPN settings

Create SSL-VPN Policy in FortiGate Firewall

Expand the Policy & Objects option, and then click on Firewall Policy.
Name: Enter an SSL VPN policy name
Outgoing Interface: Internal
Source: Click on the + icon to select SSL VPN users and groups (SSLVPN-Users and SSL-VPN).
Destination: Click on the + icon to choose the VPN address (VPN-Local-Desk) we created.
Configure security profiles as per your requirements, and then click OK.

SSL VPN policy Fortigate Firewall

With this procedure, the configuration of SSL-VPN on the FortiGate 60F firewall comes to an end.

Fortigate firewall policy

In the next article, we will configure FortiClient VPN on Windows and FortiClient VPN on Android.

Jamil
Jamilhttp://jamiltech.com
A Professional Technology Blog Writer | An energetic professional with more than 20+ years of rich experience in Technology, Planning, Designing, Installation, and Networking.
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments

what is cryptocurrency and bitcoin on How to Backup and Restore IIS Configuration
경기광주출장안마 on How to Backup and Restore IIS Configuration
영등포출장마사지 on How to Backup and Restore IIS Configuration
Twalsu light mirror for vanity on How to Backup and Restore IIS Configuration
fitspresso analysis on How to Reset Microsoft 365 Password
historical landmarks tours for history buffs on How to Add Hyper-V Server Altaro VM Backup
9780443186882 PDF download on How to Migrate Active Directory 2012 to 2022
Shaik Mohammad Jaheer on How to Enable Night Light on Windows 11