SSL VPN version 4.0 configuration diagram

Source: Internet
Author: User
Tags firewall backup

1. Introduction to SSL VPN features

1. 1 SSL VPN Feature introduction

The FortiGate SSL VPN feature uses SSL and proxy technology to enable authorized users to secure reliable Web clients, server-side applications, or other file resource sharing services. FortiGate SSL VPN works only under NAT mode, and transparent mode does not support SSL VPN functionality. FortiGate SSL VPN provides the following 2 modes of operation:

A, Web mode, remote users can use the browser in this mode of SSL VPN access to the company's internal resources, limited to HTTP/HTTPS,FTP,SMB/CIFS,TELNET,VNC,RDP services;

B, tunnel mode, the firewall will be virtual out of a "ssl.root" interface, all the traffic using SSL tunnel mode is equivalent to access this SSL VPN interface, remote users need to install an SSL VPN client software to support all applications.

1. 2 typical topological structures are as follows,

1. 3 authentication protocols supported by SSL VPN are:

Local Certification

RADIUS Certification

tacacs+ Certification

LDAP authentication

PKI Certificate Certification

Windows AD Authentication

1. 4 SSL VPN and IPSEC VPN comparisons

SSL VPN IPSEC VPN

Mainly for roaming users mainly for site direct

Security protocol based on IP layer for Web application

Mainly used in 2-point direct VPN connection is mainly used in multiple points, build VPN network

You can use a browser to install specific IPSec VPN client software

The user-based access control strategy is mainly based on the site access control strategy

No backup feature with tunnel backup and connection backup

2. Web Mode configuration

The Web-mode configuration might require several steps:

Enable SSL VPN;

New SSL VPN user

New SSL VPN User group

Establish an SSL VPN policy

Here's a detailed description of the Web mode configuration.

2. 1 Enabling SSL VPN

Open a Web browser login firewall, into the virtual private network---->SSL----> Settings, tick "Start Ssl-vpn", other configuration as needed to modify or use the default configuration, as shown below:

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.