Description | This article describes why is not possible to use LDAP user and groups in IPSEC VPN. |
Scope | FortiGate. |
Solution |
It is possible to authenticate users using XAuth with LDAP and then apply firewall policies based on the IP Pool assigned to users connecting via IPsec VPN. It allows users authenticated in LDAP to be able to connect to the VPN. This means that only members of an LDAP group, or single LDAP users will be able to authenticate and establish a connection to the IPsec VPN.
However, it is not possible to directly specify LDAP users in firewall policies. Traffic is not filtered directly by LDAP users but by the IP Pool assigned to those users. To apply user-based policies, use the IP addresses assigned to users when they connect to the VPN.
Example:
config firewall ippool end
config firewall policy
In summary:
|