Dev.to Security 🔐 Cybersecurity 👁 0 📖 4 min read

How to Set Up an SSL VPN on a FortiGate 40F (Step-by-Step)

Want to reach your local network from anywhere in the world? In this guide, I'll show you how, using a FortiGate 40F firewall and SSL VPN. Heads up: SSL VPN was removed from FortiOS 7.6.3 and later on lower-end models

How to Set Up an SSL VPN on a FortiGate 40F (Step-by-Step)

Want to reach your local network from anywhere in the world? In this guide, I'll show you how, using a FortiGate 40F firewall and SSL VPN.

Heads up: SSL VPN was removed from FortiOS 7.6.3 and later on lower-end models (including the 40F), which are pushed toward IPsec instead. This guide applies to FortiOS 7.4 and earlier (replace with your exact version).

What is a FortiGate?

FortiGate is a firewall used by enterprises around the globe. Its main job is to manage network traffic and apply policies that control what is allowed and what isn't. It also does much more: it can act as a checkpoint for antivirus scanning, capture network traffic, and create IPsec and SSL VPN tunnels.

What is an SSL VPN?

An SSL VPN lets you connect to a private network that isn't directly reachable from the internet. Traffic is encrypted with TLS (the successor to SSL) and carried over HTTPS, so it usually passes through firewalls that block other VPN protocols.

Prerequisites

  • A FortiGate 40F with admin access to the web UI
  • A Linux machine to test the connection
  • A free TCP port for the VPN (we'll use 10443)
  • (If behind a router) access to the router to configure port forwarding

Step 1: Create the user group and user

First, create the user and group that will be allowed to connect.

Go to User & Authentication → User Groups, then click Create New.

User Groups page with Create New button

Give the group a name, then add a member.

Group creation form

Click Create in the member selector. The user wizard will open. Select Local User as the type.

User wizard, local user type

Enter a username and password, then click Next.

Username and password step

On the next screen you can enable two-factor authentication. This is strongly recommended in production, since it protects you even if the password leaks. For this demo we'll skip it.

Two-factor authentication step

Make sure the user is enabled, then click Submit.

Enable user and submit

The new user will appear in the right-hand column. Select it to add it to the group's members, then click OK.

Adding the user to the group

Our user and group are ready.

Step 2: Create the SSL VPN portal

Go to VPN → SSL-VPN Portals and click Create New.

SSL-VPN Portals page

Name the portal and configure tunnel mode as shown below.

Portal name and tunnel settings

Also add an IP range. Clients connecting to the VPN will get an address from this pool.

IP range selection

Configure the IP range and click OK.

IP range configuration

Then finish the portal configuration.

Portal configuration, part 1

Portal configuration, part 2

Step 3: Configure the SSL VPN settings

Go to VPN → SSL-VPN Settings and configure the following:

  1. Enable SSL-VPN.
  2. Set the listening port to 10443. Avoid 443, since it can conflict with the management interface.
  3. Select a server certificate.
  4. Enable Redirect HTTP to SSL-VPN Portal.
  5. Restrict access to specific hosts if you can. Allowing any host is fine for a lab, but not for production.
  6. Select the IP range created earlier.
  7. In the Authentication/Portal Mapping table, add the group we created so every member is allowed to connect.

The group in my screenshots has a different name from the one we created above, so use your own.

SSL-VPN settings, part 1

SSL-VPN settings, part 2

SSL-VPN settings, part 3

SSL-VPN settings, part 4

Step 4: Create the firewall policies

With the portal and SSL VPN configured, we need two policies to control access:

  • one for traffic going out through the WAN (remote subnets)
  • one for traffic to the local subnets behind the firewall

In this example the VPN is for admins, so I give it full access. This is dangerous without two-factor authentication: if the password is compromised, an attacker gets access to every subnet. In production, follow the principle of least privilege and only allow what each user needs.

Go to Policy & Objects → Firewall Policy and click Create New.

Configure the first policy like this:

First policy, part 1

First policy, part 2

And the second policy like this:

Second policy, part 1

Second policy, part 2

In both policies, set the Source to the user group you created and to the all address.

Policy source field

Step 5: Connect to the SSL VPN

We'll use the openfortivpn command-line client. On Debian/Ubuntu:

sudo apt install openfortivpn

The first time, you need to trust the firewall's certificate. Run the command with a wrong or missing --trusted-cert and it will print the certificate's hash:

openfortivpn FIREWALL_IP:10443 -u ssl-vpn-test-user 2>&1 | grep trusted-cert

# Output:
# ERROR:      --trusted-cert 9aa9190e72e157cd09a1d4f7ea555e8eaa8c80ca555ebaf5e2af4f4351713d8

Verify that this hash matches your firewall's certificate before trusting it. Then connect using it:

sudo openfortivpn FIREWALL_IP:10443 \
  -u ssl-vpn-test-user \
  --trusted-cert 9aa9190e72e157cd09a1d4f7ea555e8eaa8c80ca555ebaf5e2af4f4351713d8

You'll be prompted for the password. Avoid -p 'PASSWORD' on the command line, since it ends up in your shell history and is visible in the process list. You can also store the settings in /etc/openfortivpn/config.

Once connected, you'll have access to every subnet the firewall can reach, both local and remote.

Step 6: Forward the port (if the firewall is behind a router)

If your FortiGate sits behind a router (for example, a home or ISP router) instead of having a public IP directly on its WAN interface, the router has to pass the VPN traffic through. Create a port forwarding rule on the router:

Setting Value
Protocol TCP
External port 10443
Internal IP The FortiGate's WAN interface IP
Internal port 10443

Then connect using the router's public IP (or a domain name pointing to it) instead of the firewall's internal IP:

sudo openfortivpn ROUTER_PUBLIC_IP:10443 -u ssl-vpn-test-user

Note: port forwarding won't work if your ISP uses CGNAT (you don't have a real public IP). If your public IP changes often, consider a dynamic DNS service.

Conclusion

You now have a working SSL VPN on your FortiGate 40F. Before using it in production, I recommend:

  • enabling two-factor authentication
  • restricting access by source host and by destination subnet
  • using a certificate from a trusted CA instead of a self-signed one

Questions or suggestions? Leave a comment below!

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.