Skip to main content
kiri
Staff & Editor
Staff & Editor
November 25, 2022

Technical Tip: Firewall policy group order and SSL VPN auth rules order do not work

  • November 25, 2022
  • 0 replies
  • 1679 views
Description This article describes why the group order on the same firewall policy and the SSL VPN auth rules order has no bearing on the auth process.
Even if it seems like a group on the same firewall policy and SSL VPN auth rules can be set in a particular order, this has no bearing in determining the group.
If a user can match multiple groups and there is no way to differentiate it, group order/SSL VPN auth rules order will not have any bearing.
Scope FortiGate 6.X, 7.X.
Solution

The order is not designed to have a bearing on selecting one group over the other in the auth process.
For this specific case, the best way to determine which group should be selected is to:


1) Differentiate this user that can match more groups by using source/dest or other parameters.
2) Split the firewall policy with multiple groups in multiple policies with a single group.
3) Use SSL VPN realms.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!