When creating a firewall policy for your SSL VPN, you will select ssl.root as the Incoming Interface. Also, source devices are not applicable to SSL VPN firewall policies.
For more information about using a virtual WAN link, please see the FortiGate Cookbook recipe
Providing remote users with access using SSL VPN, found at
docs.fortinet.com.