Using SSL tunnel VPN only from defined set of computers
We currently evaluating fortigate for using it as a client ssl vpn endpoint.
Most of our users have notebooks where they are local administrators because they have to install software most of the time.
All of this notebooks are domain joined.
When they use the ssl vpn they should be able to work like as they are connected in house into our intranet.
Only this notebooks should be able to use the ssl vpn endpoint.
Our first thought was to use computer certificates as a 2nd factor. It looks like this isn't possible because the client does not show the computer certificates.
We have user certifactes for client authentication and email signature. But they are exportable. Users could export them and use them on their private computers and successfully connect to the network.
For now the only solution we found is to register the forticlient installations which generates more costs because we need to license the forticlient without using (at least for now) any of the other features the license brings.
Are there any other solutions we could use?
If you use it, how are you using this ssl tunnel vpn solutions? Could your vpn users use any device to connect from? Do you limit the services they could use through the ssl vpn, or are they connected like they are in house in the internal network?
