Hello dears ,

how i can when user connect to ssl vpn use just thee network of ssl vpn tunnel , and stop the internet connection

Rotring has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

HI
To configure your Sangfor NGAF SSL VPN so that users can only access network resources through the VPN and block their regular internet access, you need to implement "Full Tunnel Mode" on the SSL VPN connection. This ensures that all traffic is routed through the VPN, and the user's local internet connection is effectively disabled when connected to the VPN.

Here’s how you can do it:

Steps to Force SSL VPN Traffic Through the Tunnel (Full Tunnel Mode)
1. Access the NGAF WebGUI
Log in to the Sangfor NGAF management interface using your admin credentials.
2. Configure SSL VPN Profile
Navigate to VPN > SSL VPN > SSL VPN Configuration.
Look for the Client Tunnel Mode settings. You should have the option to choose between Full Tunnel and Split Tunnel.
Full Tunnel Mode ensures that all traffic (including internet traffic) from the user’s machine goes through the VPN tunnel.
Split Tunnel Mode allows users to access both VPN resources and their local internet connection simultaneously, which is what you want to avoid.
3. Set to Full Tunnel Mode
Select Full Tunnel Mode under the Client Tunnel Mode option.
This forces all traffic (including DNS queries, internet traffic, etc.) through the SSL VPN tunnel, so the user cannot access their local internet while connected.
4. Disable Local Internet Access
To ensure that the user's internet traffic is routed through the VPN and not their local connection:
Set route policies that push the traffic destined for internet resources through the VPN gateway (this is typically done by setting the default gateway on the VPN server).
Ensure that the default route on the client machine is set to the VPN interface, forcing all traffic, including web browsing, to go through the tunnel.
5. DNS Configuration
Configure VPN DNS servers within the SSL VPN settings so that all DNS queries also go through the VPN.
This prevents users from using their local DNS settings, ensuring all traffic remains within the VPN tunnel.
6. Save and Apply the Configuration
After configuring the SSL VPN settings to use Full Tunnel Mode, save the changes and apply the configuration.
Test by connecting to the VPN from a client machine and verifying that no local internet access is available while the VPN is active.
7. Test and Monitor
After applying the changes, connect to the SSL VPN from a test device.
Ensure the user can access internal network resources through the VPN but cannot access external sites using their local internet connection.
Is this answer helpful?
Newbie861261 Lv1Posted 17 Oct 2024 17:14
  
Last edited by Newbie861261 17 Oct 2024 17:16.

you can modify client VPN settings. Idk, I did that one time and it worked.
Enrico Vanzetto Lv4Posted 18 Oct 2024 00:40
  
Hi, you have to create an application policy that denies outgoing traffic to vpn's network segment. This to ensure that external vpn users cannot reach internet if you need to.
Rotring Lv2Posted 18 Oct 2024 12:10
  
HI
To configure your Sangfor NGAF SSL VPN so that users can only access network resources through the VPN and block their regular internet access, you need to implement "Full Tunnel Mode" on the SSL VPN connection. This ensures that all traffic is routed through the VPN, and the user's local internet connection is effectively disabled when connected to the VPN.

Here’s how you can do it:

Steps to Force SSL VPN Traffic Through the Tunnel (Full Tunnel Mode)
1. Access the NGAF WebGUI
Log in to the Sangfor NGAF management interface using your admin credentials.
2. Configure SSL VPN Profile
Navigate to VPN > SSL VPN > SSL VPN Configuration.
Look for the Client Tunnel Mode settings. You should have the option to choose between Full Tunnel and Split Tunnel.
Full Tunnel Mode ensures that all traffic (including internet traffic) from the user’s machine goes through the VPN tunnel.
Split Tunnel Mode allows users to access both VPN resources and their local internet connection simultaneously, which is what you want to avoid.
3. Set to Full Tunnel Mode
Select Full Tunnel Mode under the Client Tunnel Mode option.
This forces all traffic (including DNS queries, internet traffic, etc.) through the SSL VPN tunnel, so the user cannot access their local internet while connected.
4. Disable Local Internet Access
To ensure that the user's internet traffic is routed through the VPN and not their local connection:
Set route policies that push the traffic destined for internet resources through the VPN gateway (this is typically done by setting the default gateway on the VPN server).
Ensure that the default route on the client machine is set to the VPN interface, forcing all traffic, including web browsing, to go through the tunnel.
5. DNS Configuration
Configure VPN DNS servers within the SSL VPN settings so that all DNS queries also go through the VPN.
This prevents users from using their local DNS settings, ensuring all traffic remains within the VPN tunnel.
6. Save and Apply the Configuration
After configuring the SSL VPN settings to use Full Tunnel Mode, save the changes and apply the configuration.
Test by connecting to the VPN from a client machine and verifying that no local internet access is available while the VPN is active.
7. Test and Monitor
After applying the changes, connect to the SSL VPN from a test device.
Ensure the user can access internal network resources through the VPN but cannot access external sites using their local internet connection.
NandangGozali Lv1Posted 18 Oct 2024 14:31
  
Hi @Newbie452061
Maybe you can describe more detail about your Question.

What device are you use.? is it IAG/IAM or NGAF/NFS or Sangfor SSL VPN Dedicated product.?
And how your infrastructure design for SSL VPN.? the user is company user that working in office and want to access internal resource using SSL VPN.? or the user is company user that working remotely outside from office and want to access internal resource using SSL VPN.?

If you are using SSL VPN Dedicated product I have no experience about that, because I'm using NGAF. So if you using NGAF/NSF, if your user is company user in the office and using SSL VPN untuk access the internal resources, maybe you can using Application Security Policy to restrict user access to the internet based on user IP or User ID. But if your user is company user that working remotely I think it is not possible using NGAF/NSF itelsef, because as I know that sangfor SSL VPN using split tunnel mode and not full tunnel mode (I using NGAF 8.0.47 and I can't see configuration option for change mode to split tunnel or  full tunnel, correct me if I wrong). So using split tunnel mode..laptop user will split connection between company resources and Internet, because user will using their own Internet right.? so you can't control user Internet Access if you are using NGAF/NSF itself.

Another solution maybe you can combine Sangfor SSL VPN with Sangfor SASE or maybe using SASE product itself.

Maybe another member have another solution..keep going bro.

Thanks

I Can Help:

Change

Board Leaders