Description | This article describes how to create a policy for SSL VPN without checking the source user group of the authenticated SSL VPN groups/users. Check the warning note below. |
Scope | FortiGate, SSL VPN, testing purposes. |
Solution |
This action can be performed only from the CLI.
edit *SSL VPN policy ID number* unset group end
Warning: From the GUI, it is possible to notice that an SSL VPN policy is not allowed to be created if there is a user or a user group assigned to the source addresses. And if there is a policy created without a user or a user group, it will still ask for one. This is done on purpose and is not recommended to be configured without one, the SSL VPN policies should always have configured the required users or user groups. By doing so, more security is provided to the traffic/connections. The above command should be used only for testing purposes and in some very rare cases. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.