EasyManuals Logo

Fortinet FortiGate Series Administration Guide

Fortinet FortiGate Series
764 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #39 background imageLoading...
Page #39 background image
What’s new in FortiOS Version 4.0 MR1 SSL VPN enhancements
FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903 39
http://docs.fortinet.com/ • Feedback
IP address ranges are now defined as firewall addresses
Several IP address ranges for tunnel mode SSL VPNs are defined in FortiOS 4.0 MR1
using firewall addresses and you can specify multiple ranges:
Tunnel IP ranges
In the tunnel widget configuration, the start-ip and end-ip keywords have been
removed. Instead, you specify one or more firewall addresses using the new ip-pools
keyword, like this:
config vpn ssl web portal
edit <portal_name>
config widget
edit <widget_id>
set name <name_str>
set type tunnel
set ip-pools ip_pool1 ip_pool2
end
end
You define ip_pool1 and ip_pool2 using the config firewall address
command. Only range and subnet address types are allowed.
Split tunnel IP ranges
Use the new split-tunneling-routing-address keyword to specify one or more ranges of IP
addresses that are reached through the SSL VPN, like this:
config vpn ssl web portal
edit <portal_name>
config widget
edit <widget_id>
set name <name_str>
set type tunnel
set split-tunneling enable
set split-tunneling-routing-address ip_pool1 ip_pool2
end
end
You define ip-pool1 and ip_pool2 using the config firewall address
command. Only range and subnet address types are allowed.
Tunnel mode client address ranges
In the SSL VPN settings, the tunnel-startip and tunnel-endip keywords have
been removed. Instead, use the new tunnel-ip-pools keyword to define the one or
more ranges of IP addresses reserved for remote clients:
config vpn ssl settings
set tunnel-ip-pools ip_pool1 ip_pool2
end
You define ip_pool1 and ip_pool2 using the config firewall address
command. Only range and subnet address types are allowed.

Table of Contents

Other manuals for Fortinet FortiGate Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Fortinet FortiGate Series and is the answer not in the manual?

Fortinet FortiGate Series Specifications

General IconGeneral
ModelFortiGate Series
CategoryFirewall
ThroughputVaries by model
InterfacesVaries by model
Concurrent SessionsVaries by model
VPN SupportYes
High AvailabilityYes
Firewall ThroughputVaries by model
VPN ThroughputVaries by model
IPS ThroughputVaries by model
NGFW ThroughputVaries by model
Threat Protection ThroughputVaries by model
New Sessions per SecondVaries by model
Power SupplyVaries by model
Security FeaturesFirewall, IPS, Application Control, Web Filtering, Antivirus, VPN
Virtual DomainsYes
Form FactorDesktop, Rackmount

Related product manuals