Skip to main content
Dan_Smith
New Member
July 23, 2013
Question

FortiClient Always on VPN and Certificates

  • July 23, 2013
  • 2 replies
  • 12471 views
Hi, I' m new to the Fortinet Product range and am looking at VPN solutions for my company. Ideally what I would like to achieve is always on connectivity like Direct Access with the VPN being initiated before the user has logged on to the laptop secured by a valid certificate issued individually to each machine from our internal CA (we already issue certs for corporate wireless access so using the same computer cert would be helpful). Does anyone know if this kind of scenario is supported? I can' t seem to find much documentation on the always on VPN and on certificate configuration for forticlient but maybe I' m looking in the wrong places? Any advice or assistance on this would be helpful. Thanks Dan

    2 replies

    Chris_Lin_FTNT
    Staff
    Staff
    July 25, 2013
    FortiClient supports always-on VPN for both SSL and IPSec. As to certificate, IPSec supports using certificate (X.509), without using user name and password as authentication (whereas SSL always requires user name). So you also want VPN to be connected before user logon windows?
    Dan_Smith
    Dan_SmithAuthor
    New Member
    July 26, 2013
    Hi Chris, Yes ideally, in a similar way to Direct Access such that if the user is inside the corporate environment the VPN is disabled but outside the VPN is auto initiated. So we get the benefits of a DirectAccess style solution but with out the requirement for additional kit/servers. I assume you can use a split tunnel to save on traversing into and back out of the environment for internet traffic but still have browsing history sent back to the FortiAnalyzer and policy updates pushed down to the client from the Fortigate? Dan
    Chris_Lin_FTNT
    Staff
    Staff
    July 29, 2013
    Hi, Dan, I think it' s pretty much do-able with FortiClient auto-connect and always-up feature. auto-connect will try to establish VPN once user logon Windows. Although FortiClient cannot tell whether it' s inside or outside corporate network, FortiGate VPN policy can be configured to only allow outside connections. So even FortiClient always try to connect when inside corporate network, it basically won' t affect normal usage. If your Windows has joined the domain, you can also enable VPN before logon. Chris