FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
gmanea
Staff
Staff
Article Id 196938
Description
VIP address cannot be used in SSL VPN bookmark.

Solution
This behavior is by design.

The workarounds are:

- use VIP address in SSL VPN tunnel mode
- use real server IP in SSL VPN bookmark

Since FortiOS v5.2.2, VIP objects are not allowed to be selected in SSL VPN policies if user groups are set and corresponding portal has web mode enabled.

Contributors