Created on
11-14-2019
02:32 AM
Edited on
10-22-2025
10:18 PM
By
Anthony_E
Description
This article describes the procedure to add multiple user groups in XAUTH in dial-up VPN.
Scope
FortiGate.
Solution
When any dial-up IPsec VPN configuration is created from the IPsec wizard, it will provide the option to add one user group only.


Note:
User authentication through LDAP is intended to function with XAUTH and IPsec IKEv1.
To add multiple user groups for XAUTH authentication, select Inherit from policy.
Edit: XAUTH: select the Type setting and select one of the following options:

After creating multiple firewall policies and applying user groups, specify destination addresses based on the user group. Users will be connected and, based on user group and policy, will only have access to specific destinations.


Related article:
Technical Tip: Using group based firewall policy for Dial-Up VPN to restrict network access
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.