Skip to main content
Vatsake
Visitor III
May 27, 2026
Question

FortiGate IPSec with certificate based authentication and ldap integration group based policies

  • May 27, 2026
  • 4 replies
  • 151 views

We are planning to migrate from SSL VPN to IPsec VPN using certificate-based (signature-only) authentication.

Since the VPN will be used by both employees and contractors, we need to implement group-based policy controls similar to what we currently have with SSL VPN.

I have configured the user peer with ldap-mode principal-name, which maps the certificate UPN to the LDAP user. This part is working as expected (if user is disabled, it won’t allow log in).

However, I have not been able to get LDAP group-based matching working in firewall policies.

I have 7.2.12 version at the moment, maybe newer version has this fixed?

4 replies

Sheikh
Staff
Staff
May 28, 2026

Hello ​@Vatsake,

Please check this technical document.
 


regards,

 

Sheikh

If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.
Vatsake
VatsakeAuthor
Visitor III
May 28, 2026

That's for SSL VPN

AEK
SuperUser
SuperUser
May 31, 2026

Did you check this teck tip:

 

However I’m not sure if the “User group” can be set to “Inherit from Policy” when using cert based authentication. You may try via CLI in case it doesn’t appear in WebUI.

AEK
Vatsake
VatsakeAuthor
Visitor III
June 2, 2026

If I enable EAP, that means I’d have to set EAP credentials in FortiClient also in addition to certificate. - I don’t really want that.
The certificate already belongs to the user. Why need to identify yourself twice
But I guess what I’m asking is impossible :)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!