Skip to main content

SSL-VPN on custom Interface

This explains how to setup the SSL-VPN on a FortiGate (E-Series) on a Custom Interface for better Controls.

This is done because per default, SSL-VPN Listens on the WAN Interface directly, therefor can not be controlled by any Policy.

Create Loopback Interface

image.png

image.png

image.png

Bind SSL-VPN to new Loopback Interface

image.png

image.png

Redirect SSL-VPN Traffic

We now need to make sure the SSL-VPN Traffic actually reaches the new SSL-VPN Interface. We will use a Virtual IP with Port Forwarding for that.

image.png

image.png

image.png

Allow Traffic to new Interface

image.png

image.png

image.png