FortiGate IPSec with certificate based authentication and ldap integration group based policies
We are planning to migrate from SSL VPN to IPsec VPN using certificate-based (signature-only) authentication.
Since the VPN will be used by both employees and contractors, we need to implement group-based policy controls similar to what we currently have with SSL VPN.
I have configured the user peer with ldap-mode principal-name, which maps the certificate UPN to the LDAP user. This part is working as expected (if user is disabled, it won’t allow log in).
However, I have not been able to get LDAP group-based matching working in firewall policies.
I have 7.2.12 version at the moment, maybe newer version has this fixed?
