286
01-28006-0100-20041105
Fortinet Inc.
Internet browsing through a VPN tunnel
VPN
Configuring Internet browsing through a VPN tunnel
Configure Internet browsing through a VPN tunnel be selecting advanced settings in a
IPSec Phase 2 configuration. For Internet browsing, select the Interface through
which remote VPN users can connect through the firewall to the Internet. The internet
browsing interface becomes the virtual source interface from which VPN users can
browse the Internet.
The Internet browsing interface could be port 1 and VPN users would be able to
browse the Internet using the same firewall policies as users on the network
connected to port 1 (for example, port 1
->
port 3 policies, where port 1 is connected
to the internal network and port 3 is connected to the Internet).
You can also create dedicated firewall policies just for VPN users. One way to do this
is to designate a virtual source interface just for VPN users. The virtual source
interface could be a physical interface or a VLAN sub-interface. You can add a VLAN
sub-interface just for this purpose.
In the IPSec VPN Phase 2 configuration, set Internet browsing to the virtual source
interface. Then create Internet access policies for VPN users. For example, if the
virtual source interface is VLAN_21, and port 3 is connected to the Internet, you would
require create VLAN_21
->
external firewall policies.
To configure Internet browsing through a VPN tunnel
1
Go to
VPN > IPSec > Phase 1
.
2
Add a phase 1 configuration to define the parameters used to authenticate the remote
VPN peer. See
“Phase 1” on page 250
.
3
Go to
VPN > IPSec > Phase 2
.
4
Add the phase 2 configuration to define the parameters used to create and maintain
the AutoKey VPN tunnel. See
“Phase 2” on page 254
.
5
Select Advanced.
6
If the remote gateway corresponds to a dialup user and the client broadcasts a DHCP
request for an IP address, select DHCP-IPsec. See
“System DHCP” on page 73
.
7
Set Internet browsing to the interface through which you want users to connect to the
Internet (for example, the port 1 interface).
8
Go to
Firewall > Policy
.
9
Add the required IPSec VPN encryption policy. See
“Adding firewall policies for IPSec
VPN tunnels” on page 284
.
10
If required, add additional firewall policies to support internet browsing.
11
Configure the remote VPN clients to deny split tunneling.
Note:
To support Internet browsing through a VPN, the remote VPN client must be configured to
deny split tunnelling.
Summary of Contents for FortiGate FortiGate-500A
Page 24: ...24 01 28006 0100 20041105 Fortinet Inc Customer service and technical support Introduction...
Page 46: ...46 01 28006 0100 20041105 Fortinet Inc Changing the FortiGate firmware System status...
Page 72: ...72 01 28006 0100 20041105 Fortinet Inc FortiGate IPv6 support System network...
Page 80: ...80 01 28006 0100 20041105 Fortinet Inc Dynamic IP System DHCP...
Page 110: ...110 01 28006 0100 20041105 Fortinet Inc FortiManager System config...
Page 116: ...116 01 28006 0100 20041105 Fortinet Inc Access profiles System administration...
Page 134: ...134 01 28006 0100 20041105 Fortinet Inc Shutdown System maintenance...
Page 248: ...248 01 28006 0100 20041105 Fortinet Inc CLI configuration Users and authentication...
Page 324: ...324 01 28006 0100 20041105 Fortinet Inc CLI configuration Antivirus...
Page 386: ...386 01 28006 0100 20041105 Fortinet Inc Glossary...
Page 394: ...394 01 28006 0100 20041105 Fortinet Inc Index...