Simple definition
FortiGate SSL VPN provides encrypted remote access over TLS so users can connect to company resources.
Technical definition
In FortiOS, SSL VPN access normally combines user or group authentication, portal or tunnel settings, an address pool, and firewall policies. The certificate presented by the FortiGate and the available routes also affect service operation.
How it works / role
The client establishes a TLS session with the FortiGate, authenticates, and receives the permitted connection parameters. In tunnel mode, traffic for defined networks is sent through the VPN according to routes, optional split tunneling, and security policies.
What is it used for?
Provide secure remote access to internal applications or networks without exposing those services directly to the Internet.
Practical example
A remote user authenticates to the FortiGate, receives an address from the VPN pool, and then reaches an internal server allowed by a dedicated policy.
Common issues
- The certificate is not trusted or the portal name does not match
- The user or group is not permitted by the configuration
- Routing, split tunneling, or the address pool is incorrect
- A firewall policy is missing or the client network overlaps the remote network
Key takeaway: A working SSL VPN depends on TLS, authentication, addressing, routing, and firewall policy together.