FGT1 05 SSL VPN
FGT1 05 SSL VPN
FGT1 05 SSL VPN
SSL VPN
2
Virtual Private Networks (VPN)
3
FortiGate VPN
4
SSL VPN: Web-only Mode
5
SSL VPN: Tunnel Mode
6
Tunnel Mode Split Tunneling
Internet Internal
Tunnel mode network
7
Ways of Connecting SSL VPN Tunnel Mode
• Using a browser:
o The SSL VPN web portal displays the status of the SSL VPN ActiveX
control
o The SSL VPN portal page must remain open for the tunnel to function
8
SSL VPN: Port Forward
9
Comparing SSL VPN access modes
Web-only Tunnel
10
User Bookmarks
11
User Bookmarks: Configuration
12
Portal Bookmarks
13
Realms
14
Securing SSL VPN access
15
Securing Access: Client Integrity Checking
16
Client Integrity Checking: Configuration
17
Securing Access: Restricting Host IPs
18
SSL VPN Monitor
Web-only user
19
SSL VPN Policy De-Authentication
20
Configuration Steps
21
Step 1: User Accounts and Groups
+
Token code (two factor)
22
Step 2: Configure the Portal(s)
Tunnel mode
resources
• Bookmarks, Tunnel
mode, etc.
23
SSL VPN Portal Example
24
Step 3: Connection settings
Certificate presented to
clients. Use a certificate
issued by a Certificate
Authority (CA) to avoid
web browser warnings
25
SSL VPN login vs. Administrator login
• If both features use the same port and are enabled on the
same interface, only SSL VPN login appears
26
Step 3: Tunnel Mode Client Settings
Range of IPs
assigned
to tunnels
27
Step 3: Authentication Portal Mapping
28
Step 4: Firewall Policies to/from the SSL VPN interface
29
Example: Firewall Policy
30
Step 5: Policies for traffic to internal resources
DMZ
edit 11 edit 12
set srcintf "ssl.root" set srcintf "ssl.root"
set dstintf “dmz" set dstintf “internal"
set srcaddr "SSLVPN_TUNNEL_ADDR1 " Exchange set srcaddr "SSLVPN_TUNNEL_ADDR1"
set dstaddr “Mail_Server" set dstaddr “Records_Server"
set action accept set action accept
set schedule "always" set schedule "always"
set service "ALL" set service "ALL"
set groups "Accountants" set groups "Accountants" “Teachers”
set nat enable set nat enable
next next
31
Review
VPN
SSL VPN vs. IPsec VPN
Web-only mode, tunnel mode (including split-tunneling),
and port forwarding
Methods of connecting to SSL VPN tunnels
Portals, bookmarks, and realms
Securing SSL VPN access
Monitoring SSL VPN users
Configuring SSL VPN
32