Chapter 16 SSL VPN : Introduction to SSL VPN : SSL VPN modes of operation : Web-only mode
  
Web-only mode
Web-only mode provides remote users with a fast and efficient way to access server applications from any thin client computer equipped with a web browser. Web-only mode offers true clientless network access using any web browser that has built-in SSL encryption and the Sun Java runtime environment.
Support for SSL VPN web-only mode is built into FortiOS. The feature comprises of an SSL daemon running on the FortiGate unit, and a web portal, which provides users with access to network services and resources including HTTP/HTTPS, Telnet, FTP, SMB/CIFS, VNC, RDP, and SSH.
In web-only mode, the FortiGate unit acts as a secure HTTP/HTTPS gateway and authenticates remote users as members of a user group. After successful authentication, the FortiGate unit redirects the web browser to the web portal home page and the user can access the server applications behind the FortiGate unit.
When the FortiGate unit provides services in web-only mode, a secure connection between the remote client and the FortiGate unit is established through the SSL VPN security in the FortiGate unit and the SSL security in the web browser. After the connection has been established, the FortiGate unit provides access to selected services and network resources through a web portal.
FortiGate SSL VPN web portals have a 1- or 2-column page layout and portal functionality is provided through small applets called widgets. Widget windows can be moved or minimized. The controls within each widget depend on its function. There are predefined web portals and the administrator can create additional portals.
Configuring the FortiGate unit involves selecting the appropriate web portal configuration in the user group settings. These configuration settings determine which server applications can be accessed. SSL encryption is used to ensure traffic confidentiality.
The following table lists the operating systems and web browsers supported by SSL VPN web-only mode.
Table 75: SSL VPN Web-only Mode, supported operating systems and web browsers
Operating System
Web Browser
Microsoft Windows 7 32-bit SP1
Microsoft Internet Explorer versions 8, 9, 10 and 11
Mozilla Firefox version 26
Microsoft Windows 7 64-bit SP1
Microsoft Internet Explorer versions 8, 9, 10 and 11
Mozilla Firefox version 26
Linux CentOS version 5.6 and Ubuntu version 12.0.4
Mozilla Firefox version 5.6
Mac OS X v10.7 Lion
Apple Safari version 7
Other operating systems and web browsers may function correctly, but are not supported by Fortinet.
See Also
SSL VPN modes of operation
Tunnel mode
Port forwarding mode