Skip to main content
Mateusz2
New Member
August 29, 2025
Question

How to allow traffic from outside the EU for a single AD user only

  • August 29, 2025
  • 1 reply
  • 258 views

 

Hi,
In FortiGate I blocked SSL traffic from outside the EU using local-in-policy. Now I would like to allow temporary access for a single AD user only, without enabling it for others.

What is the best way to implement such an exception? Which solution is supported by FortiGate?

Thanks in advance for your guidance!

 

1 reply

Toshi_Esumi
SuperUser
SuperUser
August 29, 2025

I don't think it's possible because the local-in-policy filtering happens BEFORE remote user authentication with like AD or other auth servers.
First thing I can think of in the situation like yours, I would provide a FGT to the user and set up site-to-site VPN from the FGT to make the user's location as a remote office.

Toshi