Skip to main content
Mohammed_Omar
New Member
May 23, 2025
Question

IPSEC Dial Up VPN and Firewall Policy Rule

  • May 23, 2025
  • 10 replies
  • 2164 views

Hello,

 

In the case of an IPSEC dial up VPN, can you select a user group in "Destination" in fortigate latest version (7.6.3) firewall policy ? I can't seem to have it for either IPSEC dial up VPN or SSL VPN in my fortigate (7.4.3). I can choose a user group only for the source.

 

Thank you

10 replies

funkylicious
SuperUser
SuperUser
May 23, 2025

you should be able to choose the group that is used for ipsec or sslvpn where the interface for ipsec or sslvpn is used.

if it's used as a source interface, then as a source and viceversa.

"jack of all trades, master of none"
Mohammed_Omar
New Member
May 23, 2025

Sorry but in the case of a destination, i cant (i can only choose from address and service, no "user") even if the interface is the correct one.

funkylicious
SuperUser
SuperUser
May 23, 2025

for destination, it would make sense for the user to not be required only the IP address.

"jack of all trades, master of none"
Yurisk
SuperUser
SuperUser
May 23, 2025

No, you cannot, neither in 7.6.3 nor in any FortOS version, and never could. Which means you are trying to achieve some goal in a wrong way, why would you need User Group as the destination? Tell us the final result you are trying to achieve. 

yurisk.info - all things Fortinet blog, no ads
Mohammed_Omar
New Member
May 23, 2025

Well if you have one IPSEC tunnel for a group that is formed by subgroups, you would like to filter in policy rules based on source as much as based on destination. for example :

IPSEC tunnel subnet of Big group A.

Group A contains small groups B and C.

If you want to add a policy rule allowing from IPSEC subnet group A to IPSEC subnet group A you cant because in the destination part there is no choosing user group.

ede_pfau
SuperUser
SuperUser
May 25, 2025

Then split the policy into multiple ones, using group B in the source field. This makes the policy specific to this usergroup.

knaveenkumar
Staff
Staff
May 25, 2025

Hi team,
only in the source you can choose user group
-Naveen 

volekbo8
New Member
May 25, 2025

Yes, I remembered that if I change something on the Tunnel side on FG, I should also change it in the same way on FortiClient. What surprised me the most was when I changed from IKEv1 Aggressive to IKEv2 there were no logs on the FortiGate side. It was as if there was no connection between my computer and FortiGate at all.

Mohammed_Omar
New Member
May 26, 2025

Well the whole idea is to have one tunnel for a group that has sub groups, i.e one tunnel for all sub groups, and then choose in firewall policy rules to allow whatever you want using either source or destination. It seems from your answers you can't select a group in a destination. What it does, is in this case, you will end up allowing traffic to go to all the subnet (i.e all groups) when you would want it to go only to some specific group.

 

It seems like the only solution from what you all said is multilple tunnels.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!