Description | This article describes how to enable SSL VPN client certificate authentication only to specific user/group. |
Scope | FortiGate. |
Solution |
1) Disable 'require client certificate' globally:
2) Enable client-cert under the authentication rule of SSL VPN settings (this option is available via CLI only):
config vpn ssl settings config authentication-rule edit <no> <----- User group that should connect with LDAP client certificate authentication. set client-cert en <----- Default is disable. next end
Note: If the users are using certificate authentication in web mode and 'require client certificate' is disabled globally, then it does not work. To work in web mode, 'require client certificate' should be enabled. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.