Question
IPSec VPN and Device Identification
I have an issue which I' m hoping someone could lead me in the right direction to fix. We have a FortiGate 100D with 42 FortiWifi 20C/40C' s connecting to it via an IPSec VPN Tunnel. We just started using Web Filtering/Application Control to restrict access to certain web sites and applications for our employees, but we are an organization that serves adults with disabilities in group home settings. Some of these individuals have computers/tablets/smartphones/etc. and connect to a wifi connection that we deploy with a basic password so they can connect and get on the web. Unfortunately the password for that wifi connection was shared with some employees who now connect there personal phones and could get on sites/applications we didn' t want them using during there shifts. As of right now no devices can get to social media, but we want to allow the individuals to get on. My thought process for a solution was to allow these devices (using MAC Addresses) to use a different policy with different security profiles which I' ve done at our main office (where the FortiGate 100D is) but the MAC addresses for devices aren' t being passed over the VPN and I' m not sure if it is even possible for that to happen and if so I' m missing where to let that happen. Does anyone have anything that can lead me in the right direction or maybe this isn' t possible at all? Thanks!
