IPsec VPN user and group based restrictions
Good evening,
We have a issue regarding a IPsec remote access VPN configuration. We now have to covert entirely to IPsec VPN (no ssl-vpn anymore) and we are having issues with configuring user and group based restrictions. We want to create 3 tunnels which will use 3 user groups which have users that have a external Radius server for authentication (everything works fine in that part). We want to create a policy for each group, which will have access to 3 servers, and then add access to other servers for specific users. We are using Fortimanager, and a sample configuration is
Incoming interface : ipsec-VPN-Tunnel
outgoing interface : local-area network
source: 172.17.0.0/28 + user1
destination: server 1, 2 and 3
Problem is, the Fortigate allows all the users in the 172.17.0.0/28 to access these resources, not only user 1. We also tried enabling the "security mode: captive portal" option on the tunnel interface and allowed only the logistics department as the group, and then modified the policy and added the logistics group as the user. When we enabled that, no users has access anywhere, so the traffic was all dropped. We also tried creating a separate policy for all users in the group but that also blocked all traffic.
Is there any tips or even better a whole tutorial or thread on this platform that discusses this issue, and any best-practices for this config.
Thank you!
