Question
SSL VPN with LDAP and AD security groups
New Fortigate 200B user here. We' re running 4.00 MR2. Have just gone through the setup process for an SSL VPN portal and its functioning fine. We are using LDAP authentication ... BUT ... What we would like to do is place users in security groups in AD and have the SSL VPN authenticate on the basis of group membership. We tried for a couple of hours to get this to work, but unsuccessfully. In the end we had to settle for allowing VPN access for a whole OU. This is okay as a temporary measure, but it just doesn' t work with our AD structure. Q1. is it possible to have SSL VPN LDAP authentication on the basis of AD security group membership? Q2. if it is possible, is there a ' trick' to the config to make this work?
