1. Introduction to SSL VPN features
1. 1 SSL VPN Feature introduction
The FortiGate SSL VPN feature uses SSL and proxy technology to enable authorized users to secure reliable Web clients, server-side applications, or other file resource sharing services. FortiGate SSL VPN works only under NAT mode, and transparent mode does not support SSL VPN functionality. FortiGate SSL VPN provides the following 2 modes of operation:
A, Web mode, remote users can use the browser in this mode of SSL VPN access to the company's internal resources, limited to HTTP/HTTPS,FTP,SMB/CIFS,TELNET,VNC,RDP services;
B, tunnel mode, the firewall will be virtual out of a "ssl.root" interface, all the traffic using SSL tunnel mode is equivalent to access this SSL VPN interface, remote users need to install an SSL VPN client software to support all applications.
1. 2 typical topological structures are as follows,
1. 3 authentication protocols supported by SSL VPN are:
Local Certification
RADIUS Certification
tacacs+ Certification
LDAP authentication
PKI Certificate Certification
Windows AD Authentication
1. 4 SSL VPN and IPSEC VPN comparisons
SSL VPN IPSEC VPN
Mainly for roaming users mainly for site direct
Security protocol based on IP layer for Web application
Mainly used in 2-point direct VPN connection is mainly used in multiple points, build VPN network
You can use a browser to install specific IPSec VPN client software
The user-based access control strategy is mainly based on the site access control strategy
No backup feature with tunnel backup and connection backup
2. Web Mode configuration
The Web-mode configuration might require several steps:
Enable SSL VPN;
New SSL VPN user
New SSL VPN User group
Establish an SSL VPN policy
Here's a detailed description of the Web mode configuration.
2. 1 Enabling SSL VPN
Open a Web browser login firewall, into the virtual private network---->SSL----> Settings, tick "Start Ssl-vpn", other configuration as needed to modify or use the default configuration, as shown below: