SSL-VPN group member failed to logged in
Firmware version is v5.2.1,build618
I have a user which is matched on a LDAP server. The user also has a FortiToken assigned, but I don't think that's relevant.
The user is a member of a firewall local group. This group is added to the SSL policy (under Source Address, Source User(s)).
When I try to log in the user through the FortiClient, I receive "Permission denied. (-455)".
The Fortigate logs: sslvpn_login_unknown_user.
I tried to set the users password to local as well, that did not work either.
However, if I add the user directly to the policy, I can log in.
It seems that the policy does not process groups, only users. Is this correct? Then what do we need groups for?