Setup Forticlient Remote Access VPN in FortiGate Firewall
Local Resources shared folders printing services
internet services
To configure SSL VPN using the GUI:
FortiGate 60E
Current version
FortiOS v6.0.6
Update version
FortiOS v6.0.10
Configure the interface and firewall address. Port1 interface connects to the internal network.
Go to Network Interface and edit the wan1
Set IP/Network Mask to 20.120.123/255.255.255.0.
Edit port1 interface and set IP/Network Mask to 168.1.99/255.255.255.0.
Click OK.
Configure user and user group.
Go to User& Device UserDefinition to create a local user sslvpnuser1.
Go to User& Device UserGroups to create a group sslvpngroup with the member sslvpnuser1.
Configure SSL VPN web portal.
Go to VPN SSL-VPN Portals to create a tunnel mode only portal my-full-tunnel-portal. Disable Split Tunneling.
SSL VPN settings configuration.
Go to VPN SSL-VPN Settings.
Choose proper Listen on Interface, in this example, wan1.
Listen on Port 10443.
Choose a certificate for ServerCertificate. The default is Fortinet_Factory.
Under Authentication/Portal Mapping, set default Portal tunnel-access for All OtherUsers/Groups.
Create new Authentication/Portal Mapping for group sslvpngroup mapping portal my-full-tunnel-portal.
SSL VPN firewall policy configuration.
Go to Policy & Objects IPv4 Policy.
Fill in the firewall policy name. In this example: sslvpn full tunnel access.
Incoming interface must be SSL-VPN tunnel interface(ssl.root).
Choose an Outgoing Interface. In this example: port1.
Set the source to all and group to sslvpngroup.
In this example, the destination is all.
Set schedule to always, service to ALL, and Action to Accept.
Click OK.
Download FortiClient from forticlient.com.
Open the FortiClient Console and go to Remote Access.
Add a new connection.
Set VPN Type to SSL VPN, set Remote Gateway to the IP of the listening FortiGate interface, in this example: 20.120.123.
Select Customize Port and set it to 10443.
Save your settings.
Use the credentials you’ve set up to connect to the SSL VPN tunnel.
After connection, all traffic except the local subnet will go through the tunnel FGT.
Go to VPN Monitor SSL-VPN Monitor to verify the list of SSL users.
In FGT, go to Log & Report Traffic Log Forward Traffic and view the details for the SSL entry.
FortiGate 60E, 60E-POE, FortiWiFi 60E, FortiGate 61E, and FortiWiFi 61E
Security Devices Pakistan
http://securitydevices.pk/
http://fb.com/sdpoffical
http://fb.com/kashifazizawan
/ kashifazizawan