IPsec with multiple NPS groups
Hello FCT/FGT admins
I have FGT 7.2.9, FCT 7.4.0 (Windows, MacOS & Linux).
Trying to configure IPsec with IKEv2, with authentication from Windows NPS, to use multiple AD groups in different firewall policies (access based on group id).
The procedure is described in the below tech tip.
Basically the authentication is working fine when tested on a sample group, and remote user can connect properly.
The above tech tip mentioned the below tech tip to configure VSA attr on NPS for group matching.
My problem is that I have multiple Windows groups (more than 10), and such case is not covered by the tech tip (only one group is given as example in the NPS tech tip). So I'm not sure but I'm afraid if it will require to configure 10 times the above config on NPS (for each group), and I hope it is not the case.
Any idea on the best and simplest way to configure NPS for multiple group matching?
