How to make Fortinet SSL VPN safe to use
Is Fortinet SSL VPN Safe to use?
Without going into ZTNA and all the requirements necessary to make that work, how can your organization add security to your existing SSL VPN?
There are lots of vulnerabilities these days that come in through flaws in SSL VPNs, not just with Fortinet but many other vendors as well.... Customers have always been worried of any exposed web interface with input boxes, since they can be a vector for injection attacks etc. Many end users lock the vpn down to a self-generated CA/cert PKI and enforce requiring a client cert from an internal CA to connect, that's better than just a password, but what else can you do?
For SSL VPN do the following (from Matt in MI/NSE7)