Skip to main content
Jan_1966
New Member
February 12, 2020
Question

Using VPN users in Security policies

  • February 12, 2020
  • 2 replies
  • 3672 views

Hi,

 

I am new to fortigate and just configured Remote access VPN for FortiClient to our FortiGate cluster. I created Firewall rules for the IP Address pool to the internal network, however some rules I like to narrow down for specific VPN users.

 

I Have added 2 Ldap users to the Firewall which are also using FortiTokens for MFA.

 

 

For example I want only user1 to be able to access internet in the following configuration. Is it just a matter of adding User1 to the source of the rule?

 

edit "User1" set type ldap set two-factor fortitoken set fortitoken "xxxxxxxxxxxxxx" set email-to "user1@mail.com" set ldap-server "Ldap-server"

edit 245 set name "RA_Users Web Access" set uuid 13c77ac4-3ca4-51ea-d2bd-4dd6af20a26e set srcintf "RAVPN" set dstintf "Untrust" set srcaddr "RA_IP-pool" set dstaddr "all" set action accept set schedule "always" set service "ALL" set utm-status enable set logtraffic all set fsso disable set comments "RA Users Web Access policy" set av-profile "xxxxx" set webfilter-profile "xxxxxxxx" set ips-sensor "default" set ssl-ssh-profile "certificate-inspection" set nat enable

 

Many thanks,

 

Jan

    2 replies

    makco10
    Explorer II
    February 12, 2020

    Hello,

     

    You need to add a group with that user selected in the VPN config:

     

    https://kb.fortinet.com/kb/documentLink.do?externalID=FD36413

     

    Regards.

    Jan_1966
    Jan_1966Author
    New Member
    February 12, 2020

    Thanks Makco10,

     

    I'll have a look into that.

     

    Jan

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!