How to Set Up an SSL VPN on a FortiGate 40F (Step-by-Step)
Want to reach your local network from anywhere in the world? In this guide, I'll show you how, using a FortiGate 40F firewall and SSL VPN. Heads up: SSL VPN was removed from FortiOS 7.6.3 and later on lower-end models
Want to reach your local network from anywhere in the world? In this guide, I'll show you how, using a FortiGate 40F firewall and SSL VPN.
Heads up: SSL VPN was removed from FortiOS 7.6.3 and later on lower-end models (including the 40F), which are pushed toward IPsec instead. This guide applies to FortiOS 7.4 and earlier (replace with your exact version).
What is a FortiGate?
FortiGate is a firewall used by enterprises around the globe. Its main job is to manage network traffic and apply policies that control what is allowed and what isn't. It also does much more: it can act as a checkpoint for antivirus scanning, capture network traffic, and create IPsec and SSL VPN tunnels.
What is an SSL VPN?
An SSL VPN lets you connect to a private network that isn't directly reachable from the internet. Traffic is encrypted with TLS (the successor to SSL) and carried over HTTPS, so it usually passes through firewalls that block other VPN protocols.
Prerequisites
- A FortiGate 40F with admin access to the web UI
- A Linux machine to test the connection
- A free TCP port for the VPN (we'll use
10443) - (If behind a router) access to the router to configure port forwarding
Step 1: Create the user group and user
First, create the user and group that will be allowed to connect.
Go to User & Authentication → User Groups, then click Create New.
Give the group a name, then add a member.
Click Create in the member selector. The user wizard will open. Select Local User as the type.
Enter a username and password, then click Next.
On the next screen you can enable two-factor authentication. This is strongly recommended in production, since it protects you even if the password leaks. For this demo we'll skip it.
Make sure the user is enabled, then click Submit.
The new user will appear in the right-hand column. Select it to add it to the group's members, then click OK.
Our user and group are ready.
Step 2: Create the SSL VPN portal
Go to VPN → SSL-VPN Portals and click Create New.
Name the portal and configure tunnel mode as shown below.
Also add an IP range. Clients connecting to the VPN will get an address from this pool.
Configure the IP range and click OK.
Then finish the portal configuration.
Step 3: Configure the SSL VPN settings
Go to VPN → SSL-VPN Settings and configure the following:
- Enable SSL-VPN.
- Set the listening port to 10443. Avoid 443, since it can conflict with the management interface.
- Select a server certificate.
- Enable Redirect HTTP to SSL-VPN Portal.
- Restrict access to specific hosts if you can. Allowing any host is fine for a lab, but not for production.
- Select the IP range created earlier.
- In the Authentication/Portal Mapping table, add the group we created so every member is allowed to connect.
The group in my screenshots has a different name from the one we created above, so use your own.
Step 4: Create the firewall policies
With the portal and SSL VPN configured, we need two policies to control access:
- one for traffic going out through the WAN (remote subnets)
- one for traffic to the local subnets behind the firewall
In this example the VPN is for admins, so I give it full access. This is dangerous without two-factor authentication: if the password is compromised, an attacker gets access to every subnet. In production, follow the principle of least privilege and only allow what each user needs.
Go to Policy & Objects → Firewall Policy and click Create New.
Configure the first policy like this:
And the second policy like this:
In both policies, set the Source to the user group you created and to the all address.
Step 5: Connect to the SSL VPN
We'll use the openfortivpn command-line client. On Debian/Ubuntu:
sudo apt install openfortivpn
The first time, you need to trust the firewall's certificate. Run the command with a wrong or missing --trusted-cert and it will print the certificate's hash:
openfortivpn FIREWALL_IP:10443 -u ssl-vpn-test-user 2>&1 | grep trusted-cert
# Output:
# ERROR: --trusted-cert 9aa9190e72e157cd09a1d4f7ea555e8eaa8c80ca555ebaf5e2af4f4351713d8
Verify that this hash matches your firewall's certificate before trusting it. Then connect using it:
sudo openfortivpn FIREWALL_IP:10443 \
-u ssl-vpn-test-user \
--trusted-cert 9aa9190e72e157cd09a1d4f7ea555e8eaa8c80ca555ebaf5e2af4f4351713d8
You'll be prompted for the password. Avoid -p 'PASSWORD' on the command line, since it ends up in your shell history and is visible in the process list. You can also store the settings in /etc/openfortivpn/config.
Once connected, you'll have access to every subnet the firewall can reach, both local and remote.
Step 6: Forward the port (if the firewall is behind a router)
If your FortiGate sits behind a router (for example, a home or ISP router) instead of having a public IP directly on its WAN interface, the router has to pass the VPN traffic through. Create a port forwarding rule on the router:
| Setting | Value |
|---|---|
| Protocol | TCP |
| External port | 10443 |
| Internal IP | The FortiGate's WAN interface IP |
| Internal port | 10443 |
Then connect using the router's public IP (or a domain name pointing to it) instead of the firewall's internal IP:
sudo openfortivpn ROUTER_PUBLIC_IP:10443 -u ssl-vpn-test-user
Note: port forwarding won't work if your ISP uses CGNAT (you don't have a real public IP). If your public IP changes often, consider a dynamic DNS service.
Conclusion
You now have a working SSL VPN on your FortiGate 40F. Before using it in production, I recommend:
- enabling two-factor authentication
- restricting access by source host and by destination subnet
- using a certificate from a trusted CA instead of a self-signed one
Questions or suggestions? Leave a comment below!
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.




















