How is traffic routed onto an SSL VPN tunnel from the FortiGate unit side?
A static route must be configured by the administrator using the ssl.root interface as the outgoing
Assignment of an IP address to the client causes a host route to be added to the FortiGate unit’s
kernel routing table.
A route back to the SSLVPN IP pool is automatically created on the FortiGate unit.
The FortiGate unit adds a route based upon the destination address in the SSL VPN firewall policy.