Skip to main content
suniokera
Visitor
June 5, 2026
Question

Forticlient IPSEC, Map usergroups to different subnets

  • June 5, 2026
  • 3 replies
  • 149 views

Hi,

I've been setting up alot of Forticlient with SSL-VPN but now when it's depricated I've need to set it up with IPSEC.

When doing the SSL-VPN option we had the possibility to map different usergroups to different IP subnets with the "SSL-VPN Portals".

Is there a way of doing this with IPSEC VPN?

What I want to accomplish is to have Forticlient users connected to a central FG and that FG works as the HUB in a HUB n SPOKE topology.
At the spokes be able to assign different firewall policys based on source IP subnet.

    3 replies

    msanjaypadma
    Staff
    Staff
    June 5, 2026

    Hi ​@suniokera ,

    Based on my knowledge, the SSL VPN portal feature is not available with Dial-up IPSec VPN. However, you can assign IP addresses to users using based on client identifier. Please refer to the following article for further details.


    Or  if you want to control or restrict traffic in that case, you can use the "Inherit from policy" option in Dial-up IPSec VPN. Additionally, you can apply a specific user group for interesting subnets to manage access and traffic flow effectively. This approach allows you to enforce policies based on user groups and destination subnet configurations efficiently.

    If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.

    Thanks,
    Mayur Padma

    Thanks, Mayur Padma
    msanjaypadma
    Staff
    Staff
    June 5, 2026

    reference link : 

     

    Thanks, Mayur Padma
    Toshi_Esumi
    SuperUser
    SuperUser
    June 5, 2026

    Another option is similar to SSL-VPN’s realm. Since phase1-interface’s mode-config defines client IPs, separating phase1-interfaces per usergroup by using peerID/localID between the clients and the FGT. Since the FortiClient side needs to have a local ID, which represents a usergroup, pre-configured, it’s quite similar for SSL-VPN’s relm and its portal.

    Toshi 

    jasonmarie8
    New Member
    June 7, 2026

    Interesting question if FortiClient IPsec supports group-based policies on your FortiGate version, mapping users to different address pools should be possible and would keep access management as organized as TT789 web.