Skip to main content
BensonLEI
New Member
December 11, 2020
Solved

Specific SSLVPN user exclusive to 'Limit access to specific hosts'

  • December 11, 2020
  • 1 reply
  • 13981 views

Hi, guys,

 

The company Fortigate is configured the SSL-VPN Settings 'Limit access to specific hosts'.

 

But boss wants to SSLVPN to company from anywhere, is it possible to configure the specific user exclusive to this limit ?

 

Any advice ?

 

Many thanks

 

 

 

 

    Best answer by Yurisk

    Hi Benson,

    I don't think it is possible, if I get you right - you limit access to the VPN SSL portal(s) by source IP address of the clients? If so, then this configuration is global for the SSL VPN service, and I don't see an option to make it otherwise. Only separate VDOMs for each group of users.  

    Realms allow separation per User Group/URL, but AFTER ANY client from the Internet reached the VPN SSL port already. Basically it is the same as mapping different User Groups on Fortigate to different portals with no limit  to specific hosts - if you limit (or not) access to Specific Hosts, you limit (or not, accordingly) access to all portals/realms at once. This is configuration-wise, I haven't tried to validate on actual Fortigate though.

     

    HTH,

    Yuri

     

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    December 11, 2020

    Use realms to have different user groups.

    https://docs.fortinet.com...72/ssl-vpn-multi-realm

    BensonLEI
    BensonLEIAuthor
    New Member
    December 12, 2020

    Hi, Toshi,

     

    We shall check and verify this solution, thx so much for your information.

     

    Cheers

    Yurisk
    SuperUser
    YuriskAnswer
    SuperUser
    December 13, 2020

    Hi Benson,

    I don't think it is possible, if I get you right - you limit access to the VPN SSL portal(s) by source IP address of the clients? If so, then this configuration is global for the SSL VPN service, and I don't see an option to make it otherwise. Only separate VDOMs for each group of users.  

    Realms allow separation per User Group/URL, but AFTER ANY client from the Internet reached the VPN SSL port already. Basically it is the same as mapping different User Groups on Fortigate to different portals with no limit  to specific hosts - if you limit (or not) access to Specific Hosts, you limit (or not, accordingly) access to all portals/realms at once. This is configuration-wise, I haven't tried to validate on actual Fortigate though.

     

    HTH,

    Yuri

     

    yurisk.info - all things Fortinet blog, no ads