Question
Remote Access VPN based on AD group membership
I'm trying to setup a 200F so that multiple AD groups can connect to the site using FortiClient (IPsec not SSL) for VPN access. Group1 should be allowed to a subset of ips, group2 a different set of ips, etc. Should I just create the groups on the FGT and then make multiple rules from the VPN zone to LAN and just call the respective group in the source for each 1? Or will that match all users regardless since they will have the same source up(from the DHCP pool)?
