Fortinet FORTIOS V3.0 MR7 User Manual
Page 55
Configuring a FortiGate SSL VPN
Granting unique access permissions for SSL VPN tunnel user groups
FortiOS v3.0 MR7 SSL VPN User Guide
01-30007-0348-20080718
55
set tolerance 1
end
config sslvpn-os-check-list "windows-xp"
set action allow
end
set member "u1"
set sslvpn-split-tunneling enable
set sslvpn-http enable
next
end
config firewall policy
edit 1
set srcintf "internal"
set dstintf "external"
set srcaddr "all"
set dstaddr "172.18.8.0/24"
set action ssl-vpn
set schedule "always"
set service "ANY"
set groups "g1"
next
end
Granting unique access permissions for SSL VPN tunnel user
groups
For situations where there is a requirement for more than one user to be permitted
tunnel mode access, the key is to split the tunnel IP range into sub-IP ranges,
where each user group (with the user as a member) is assigned a dedicated IP
range (with no overlap) and therefore can have different access permissions.
Figure 13: SSL VPN configuration for unique access permissions
- FortiOS 3.0 (46 pages)
- FortiGate 5001A-DW (40 pages)
- FortiLog-800 (124 pages)
- FortiMail-100 (2 pages)
- Version 3.0 (88 pages)
- FortiAnalyzer FortiDB-400B (2 pages)
- FortiGate 100 (272 pages)
- FortiGate 310B (62 pages)
- FortiGate 50B-LENC (2 pages)
- FortiGate 620B (62 pages)
- FORTIMAIL-5000 (2 pages)
- FortiMail-2000A (2 pages)
- FortiGate 3000 (3 pages)
- Network Device IPS (62 pages)
- FortiGate v3.0 MR7 (66 pages)
- FortiDB-1000B (2 pages)
- IPSec VPN Version 4.1 (30 pages)
- FortiBridge 2002 (2 pages)
- FortiBridge 2002F (2 pages)
- FortiGate 224B (54 pages)
- FortiGate 5050-R (28 pages)
- FortiGate 5020 (14 pages)
- FortiMail 3.0 MR4 (368 pages)
- FortiGate-5000 (77 pages)
- FortiGate 310B-LENC (2 pages)
- FortiGate ASM-CX4 (1 page)
- FortiAnalyzer 1000B (2 pages)
- FortiGuard Analysis 1.2.0 (76 pages)
- ASM-CE4 (1 page)
- FortiGate 50A (272 pages)
- FSAE (20 pages)
- FortiGate 5140-R (32 pages)
- FortiGate-800 (336 pages)
- FortiGate 3600A (2 pages)
- FortiGate 3016B (2 pages)
- FortiGate 5001FA2-LENC (34 pages)
- FortiAnalyzer 3.0 MR7 (234 pages)
- FortiGate 110C (56 pages)
- FortiGate ASM-FX2 (1 page)
- FortiGate 3810A-LENC (2 pages)
- FortiGate 60B (66 pages)
- FortiGate 1000A-LENC (2 pages)
- FortiGate 5050 (26 pages)
- FortiDB-2000B (2 pages)