Chapter 16 SSL VPN for FortiOS 5.0 : Setup examples : Multiple user groups with different access permissions example : General configuration steps
  
General configuration steps
1. Create firewall addresses for
the destination networks
two non-overlapping tunnel IP address ranges that the FortiGate unit will assign to tunnel clients in the two user groups
2. Create two web portals.
3. Create two user accounts, user1 and user2.
4. Create two user groups. For each group, add a user as a member and select a web portal. In this example, user1 will belong to group1, which will be assigned to portal1.
5. Create security policies:
two SSL VPN security policies, one to each destination
two tunnel-mode policies to allow each group of users to reach its permitted destination network
6. Create the static route to direct packets for the users to the tunnel.