FortiClient Autoconnect using Entra - Exclusions or timeout options?
Hello,
We have been testing IPsec dialup connections using autoconnect and Entra ID credentials and so far it has worked pretty well. One area of concern is how to exclude situations where we may not want the auto connect to kick off (IE, local admin login or a user login that is not a member of the VPN group).
We are using EMS to configure FortiClient on Windows devices. We have the VPN tunnel configured for auto connect only when off-fabric which covers a majority of these one off situations but is there a better way to exclude users/situations from the auto connection? Maybe something like "stop auto connection after 3 failed attempts"? We have always up max tries set to 3 but this seems to only cover reconnect attempts.
Another thought was creating an additional remote user group on the firewall as a "catch all" group for users who are not members of the defined VPN groups and allow them to establish a vpn connection but go out the WAN only. Local accounts off-fabric would still get the endless connection failures i would assume.
In the current configuration, logging into Windows using an account that is not a member of the VPN group results in endless connection attempts/failures.
