Remote workforce security requires robust access controls and encrypted communication channels. A fundamental task for network engineers is setting up enterprise remote access using a solid FortiGate SSL VPN configuration. This guide explains how to build a production-grade FortiGate SSL VPN environment in split-tunnel mode using local user authentication, custom portals, and firewall security policies.

Real-Life Scenario

Acme Corporation needs to grant secure access to remote engineers who require connection to internal corporate applications hosted in the primary data center. The internal subnet is 10.0.1.0/24.

To optimize bandwidth usage and reduce firewall processing loads, company policy mandates split tunneling. Only traffic destined for corporate subnets must traverse the encrypted tunnel. All general internet browsing should exit directly through the remote user’s local internet connection.

We will configure a FortiGate firewall to handle inbound SSL VPN connection requests on its public WAN interface, authenticate users against a designated local user group, assign IP addresses from a dedicated virtual pool, and enforce restrictive access rules using firewall policies.

Lab Topology

The following diagram illustrates the network layout and logical boundaries for this deployment:

+-------------------------+
|   Remote User Client    |
| External IP: 198.51.100.50 |
+------------+------------+
             |
             | Internet / Untrusted WAN
             v
+------------+------------+
|  FortiGate Firewall     |
| Interface: port1        | (WAN: 198.51.100.1/24)
| Interface: port2        | (LAN: 10.0.1.1/24)
| Virtual UI: ssl.root    | (SSL VPN Tunnel Interface)
+------------+------------+
             |
             | Internal Corporate Network
             v
+------------+------------+
| Internal Servers Network|
| Subnet: 10.0.1.0/24     |
+-------------------------+

Example Addressing and Objects

The table below outlines the IP address assignments, interface names, and policy objects used throughout this tutorial. Adapt these values to match your production environment.

Object / Item Name Type / Value Description
port1 Physical WAN Interface Public WAN interface receiving remote client connections (IP: 198.51.100.1/24).
port2 Physical LAN Interface Internal trusted interface connected to corporate subnets (IP: 10.0.1.1/24).
ssl.root Virtual Interface Dynamic logical interface created by FortiOS for all SSL VPN traffic.
SSLVPN_TUNNEL_POOL IP Range (10.100.10.100 – 10.100.10.200) Virtual IP address range leased to remote SSL VPN clients.
ADDR_CORP_LAN Subnet (10.0.1.0/24) Internal corporate network object made accessible over the VPN.
vpnuser1 Local User Example user account created for remote client authentication.
Remote_VPN_Group User Group Security group assigned to the custom SSL VPN portal mapping rule.
Split_Tunnel_Portal SSL VPN Portal Portal profile controlling tunnel mode settings and split-tunnel routes.

Prerequisites

  • FortiOS Version Awareness: Commands and GUI paths in this guide reflect FortiOS 7.x builds. Starting in FortiOS 7.2 and 7.4, web portal features and hardware SSL acceleration capabilities vary significantly across entry-level and high-performance models. Verify feature support for your specific platform.
  • WAN Accessibility: Ensure public traffic reaches your WAN interface on the designated listening port (e.g., port 10443) and is not blocked upstream.
  • Server Certificate: Obtain a valid digital certificate issued by a trusted public Certificate Authority (CA). While default or self-signed factory certificates function for testing, they trigger security warnings in FortiClient.
  • Internal Routing: Internal routers and core switches must know how to route return traffic for the SSL VPN client address pool (10.100.10.0/24) back to the FortiGate firewall, unless policy NAT is applied.

Step-by-Step GUI Configuration

Step 1: Create IP Address Objects and VPN Range

  1. Navigate to Policy & Objects > Addresses.
  2. Click Create New > Address.
  3. Configure the protected internal network object:
    • Name: ADDR_CORP_LAN
    • Type: Subnet
    • IP/Netmask: 10.0.1.0/255.255.255.0
    • Interface: Any
  4. Click OK.
  5. Click Create New > Address Range (or Address object depending on FortiOS build).
  6. Configure the IP pool for VPN clients:
    • Name: SSLVPN_TUNNEL_POOL
    • Type: IP Range
    • IP Range: 10.100.10.100-10.100.10.200
  7. Click OK.

Step 2: Create User and Security Group

  1. Navigate to User & Authentication > User Definition.
  2. Click Create New, select Local User, and click Next.
  3. Enter a Username (e.g., vpnuser1) and set a secure Password. Click Next.
  4. Optionally add an email address, then complete the wizard by clicking Submit.
  5. Navigate to User & Authentication > User Groups.
  6. Click Create New.
  7. Set the Name to Remote_VPN_Group.
  8. Under Members, click + and select vpnuser1.
  9. Click OK to save the group.

Step 3: Configure the SSL-VPN Portal

  1. Navigate to VPN > SSL-VPN Portals.
  2. Click Create New to build a dedicated profile (or edit full-access).
  3. Set the Name to Split_Tunnel_Portal.
  4. Disable Enable Web Mode if web portal access is not required or supported on your model.
  5. Enable Tunnel Mode.
  6. Enable Enable Split Tunneling.
  7. Set Routing Address to ADDR_CORP_LAN. This instructs FortiClient to install routes only for this internal subnet.
  8. Set Source IP Pools to SSLVPN_TUNNEL_POOL.
  9. Click OK.

Step 4: Configure Global SSL-VPN Settings

  1. Navigate to VPN > SSL-VPN Settings.
  2. Under Connection Settings:
    • Listen on Interface(s): Select port1.
    • Listen on Port: Enter 10443 (avoid using default TCP 443 to eliminate conflicts with HTTPS administrative management).
    • Server Certificate: Select your trusted certificate (e.g., Fortinet_Factory for lab tests only).
  3. Under Tunnel Settings:
    • Assign IP Ranges: Select SSLVPN_TUNNEL_POOL.
  4. Under Authentication/Portal Mapping:
    • Set Default Portal to web-access or no-access (restricts unmapped users).
    • Click Create New to add a mapping rule:
      • User Groups: Remote_VPN_Group
      • Portal: Split_Tunnel_Portal
  5. Click Apply at the bottom of the page.

Step 5: Create Firewall Policy

  1. Navigate to Policy & Objects > Firewall Policy.
  2. Click Create New.
  3. Set the following fields:
    • Name: Allow_SSLVPN_to_CorpLAN
    • Incoming Interface: ssl.root (the logical SSL VPN interface)
    • Outgoing Interface: port2 (internal LAN interface)
    • Source: Select both SSLVPN_TUNNEL_POOL and the Remote_VPN_Group group.
    • Destination: ADDR_CORP_LAN
    • Schedule: always
    • Service: Select specific required services, or select ALL for testing.
    • Action: ACCEPT
    • NAT: Disable NAT if internal routers hold a static route for 10.100.10.0/24 returning to the FortiGate. Enable NAT if internal servers lack reverse routing.
  4. Enable Log Allowed Traffic (select All Sessions during testing).
  5. Click OK.

CLI Configuration Section

For engineers who prefer the command-line interface, the entire setup can be implemented using the following structured FortiOS syntax.

1. Address Objects and IP Pool

config firewall address
    edit "ADDR_CORP_LAN"
        set subnet 10.0.1.0 255.255.255.0
    next
    edit "SSLVPN_TUNNEL_POOL"
        set type iprange
        set start-ip 10.100.10.100
        set end-ip 10.100.10.200
    next
end

2. User and Authentication Group

config user local
    edit "vpnuser1"
        set type local
        set passwd SecretPassword123!
    next
end

config user group
    edit "Remote_VPN_Group"
        set member "vpnuser1"
    next
end

3. SSL VPN Portal

config vpn ssl web portal
    edit "Split_Tunnel_Portal"
        set tunnel-mode enable
        set ipv6-tunnel-mode disable
        set split-tunneling enable
        set split-tunneling-routing-address "ADDR_CORP_LAN"
        set ip-pools "SSLVPN_TUNNEL_POOL"
    next
end

4. Global SSL VPN Settings

config vpn ssl settings
    set reqclientcert disable
    set servercert "Fortinet_Factory"
    set tunnel-ip-pools "SSLVPN_TUNNEL_POOL"
    set source-interface "port1"
    set source-address "all"
    set port 10443
    set default-portal "no-access"
    config authentication-rule
        edit 1
            set groups "Remote_VPN_Group"
            set portal "Split_Tunnel_Portal"
        next
    end
end

5. Firewall Policy Rules

config firewall policy
    edit 10
        set name "Allow_SSLVPN_to_CorpLAN"
        set srcintf "ssl.root"
        set dstintf "port2"
        set action accept
        set srcaddr "SSLVPN_TUNNEL_POOL"
        set dstaddr "ADDR_CORP_LAN"
        set schedule "always"
        set service "ALL"
        set groups "Remote_VPN_Group"
        set logtraffic all
    next
end

How the Traffic Flows

Understanding how FortiOS processes SSL VPN packets helps tremendously during design and troubleshooting:

  1. Session Initiation: The remote client initiates a TLS connection from public IP 198.51.100.50 to 198.51.100.1:10443 over physical interface port1.
  2. Authentication & Portal Assignment: FortiOS completes the SSL/TLS handshake and prompts the client for credentials. Upon receiving vpnuser1, the authentication daemon (fnbamd) validates the username and group. The firewall assigns Split_Tunnel_Portal rules to the user.
  3. Tunnel Creation & IP Allocation: FortiOS assigns a virtual IP address (e.g., 10.100.10.100) from SSLVPN_TUNNEL_POOL to the host’s virtual FortiClient adapter. The client receives route instructions directing traffic for 10.0.1.0/24 into the virtual adapter.
  4. Packet Ingress & Routing Lookup: When the client pings an internal server at 10.0.1.10, packets enter FortiGate logically on the virtual ssl.root interface. FortiOS performs a route lookup and selects port2 as the egress interface.
  5. Firewall Policy Matching: FortiOS checks its active session state and policy list. It evaluates policy ID 10:
    • Source interface: ssl.root
    • Source IP: 10.100.10.100
    • Source Group: Remote_VPN_Group
    • Destination interface: port2
    • Destination IP: 10.0.1.10
  6. Egress and Return Processing: Packet checks succeed and exit via port2. The server replies to 10.100.10.100. FortiGate receives this return packet on port2, matches the stateful session entry, encapsulates it inside the TLS tunnel, and forwards it back out port1 to the remote user.

Verification

Confirm proper tunnel operation using both GUI and CLI options.

1. GUI Status Verification

Navigate to VPN > Monitor > SSL-VPN Monitor. The active dashboard displays connected users, public client IP addresses, leased tunnel IP addresses, and real-time bandwidth usage.

2. CLI Monitor Command

Execute the following command to review connected users and active session parameters directly:

get vpn ssl monitor

Expected output listing actively connected tunnel clients:

SSL-VPN sessions:
Index User      Group            Auth Type Subnet         IP            Vip
0     vpnuser1  Remote_VPN_Group 1         10.100.10.100  198.51.100.50 10.100.10.100

3. Client-side Routing Checks

On the remote Windows client workstation, open Command Prompt and check active routes:

route print

Confirm that a specific route exists for 10.0.1.0/24 pointing to the assigned virtual gateway address, while 0.0.0.0/0 still points to the local physical router gateway.

Troubleshooting Workflow

If users encounter connection failures, follow a structured diagnostic process.

Step 1: Check Tunnel & Authentication Daemons

To inspect SSL VPN engine activity and user authentication in real time, enable the application debug daemons.

CAUTION: Verbose debug output increases system CPU loads and may display traffic details. Run debug commands briefly during troubleshooting windows, and always turn them off when finished.

diagnose debug application sslvpn -1
diagnose debug application fnbamd -1
diagnose debug enable

Review the CLI stream while the user attempts a connection:

  • If you see password validation failures, recheck user credentials or group membership.
  • If you see portal allocation errors, verify that config vpn ssl settings maps the user group to a valid portal.

Disable debug tracing immediately after capturing relevant logs:

diagnose debug disable
diagnose debug reset

Step 2: Trace Firewall Policy Packet Handling

If the VPN client connects successfully but cannot reach internal servers, trace packet movement through the kernel using flow debug commands.

diagnose debug flow filter saddr 10.100.10.100
diagnose debug flow show function-name enable
diagnose debug flow trace start 20
diagnose debug enable

Have the user ping internal address 10.0.1.10. Look for the following symptoms in the output:

  • Denied by forward policy check: Indicates policy creation errors. Verify that policy ID 10 lists ssl.root as incoming interface and matches the correct user group/address objects.
  • Reverse path check fail or unresolved return routing: Indicates internal devices do not know how to reach 10.100.10.0/24. Enable NAT on the firewall policy temporarily or add static routes to internal networks.

Clean up flow tracing once complete:

diagnose debug disable
diagnose debug reset

Common Mistakes

  • Omitting User Groups from Firewall Policy: Adding a user group in config vpn ssl settings handles connection authentication, but traffic will still be dropped if the firewall policy source field does not also include the required group or address object.
  • Port Conflicts: Configuring SSL VPN to listen on TCP port 443 while local HTTPS administrative access or VIP forwarding rules also use port 443 creates port contention, leading to erratic connection failures.
  • Missing Routing for IP Pools: If NAT is disabled on the firewall policy, internal corporate core switches and destination hosts must hold static routes directing client pool subnets (10.100.10.0/24) back to the FortiGate firewall’s internal interface IP.
  • Self-signed Certificate Mismatches: Relying on factory-default SSL certificates causes client connection prompts or strict warnings on modern operating systems. Always use a proper domain certificate signed by an enterprise or public CA.

Production Considerations

When preparing your FortiGate SSL VPN configuration for production deployment, address these key security and architecture operational factors:

  • Multi-Factor Authentication (MFA): Local passwords alone present security risks. Enforce FortiToken, Radius, or SAML-based single sign-on (such as Microsoft Entra ID) to require secondary authentication factors.
  • FortiOS Hardware/Software Support: Note that web-mode SSL VPN capabilities are deprecated or removed on several entry-level FortiGate models running newer FortiOS releases (e.g., FortiOS 7.2/7.4 on lower RAM units). Plan to use full tunnel mode with the FortiClient endpoint agent.
  • Custom Listening Ports: Avoid using standard network service ports. Change the default SSL VPN listening port from 443 to a non-standard port such as 10443 to reduce automated scanning noise from untrusted public addresses.
  • Restricted Ciphers and TLS Versions: Limit connection negotiation to TLS 1.2 and TLS 1.3 to comply with corporate compliance and security baseline rules. Eliminate weak ciphers from the global SSL VPN settings.
  • Host Security Checks: Enforce endpoint compliance and post-connection checks by integrating FortiGate with FortiClient EMS to ensure incoming client devices meet minimum patch and antivirus standards.

Related FortiGate Guides

Summary

Setting up an enterprise-grade FortiGate SSL VPN requires careful coordination between user authentication, logical virtual interfaces, routing rules, and stateful firewall policies. For the next troubleshooting step, see FortiGate IPsec VPN troubleshooting and FortiGate site-to-site IPsec VPN configuration. By deploying split-tunneling portals, organizing users into distinct groups, and mapping policies correctly across the ssl.root logical interface, network administrators can deliver safe, flexible, and reliable remote access connections to internal corporate networks.