This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.
Hello to all
I will appreciate having your assistance to find the best practice to assign static IP addresses to users connecting tunnel-mode SSL VPN.
my customer asks that each SSL VPN user must always get the same unique IP address which is never assigned to any other user.
I try to find the answer in
FortiOS™ Handbook - Authentication
http://docs.fortinet.com/uploaded/files/1937/fortigate-authentication-52.pdf
FortiOS™ Handbook - SSL VPN
http://docs.fortinet.com/uploaded/files/3603/fortigate-sslvpn-56.pdf
but I cant's find any explanation how to do it
Thank you for your help
Best Regards
Hillel Kobrovski
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
does anybody know if using RADIUS authentication with special VSA ( Vendor Specific Attribute ) can help me solve the problem?
where can I find formal best practice instructions how to implement this kind of configuration with Microsoft Radius (IAS)?
page 22-23 from " FortiOS™ Handbook - Authentication "
FortiOS supported RADIUS attributes
RADIUS attribute-value pairs
RADIUS packets include a set of attribute-value pairs (AVP) to identify information about the user, their location
and other information. The FortiGate unit sends the following RADIUS attributes.
Radius Attribute #4 | Name = Framed-IP-Address | Description = Address to be configured for the user | AVP Type = 8
Thank You for your help
Best Regards
Hillel Kobrovski
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.