FortiSASE
FortiSASE delivers both a consistent security posture and an optimal user experience for users working from anywhere. Secure your hybrid workforce by closing security gaps, plus simplify operations.
anderson_yee
Staff
Staff
Article Id 338897
Description This article describes how to push custom VPN tunnels (SSL or IPSec VPN) to FortiSASE managed endpoints.
Scope FortiSASE, Custom VPN, Endpoint profiles.
Solution

Prerequisites:

  • Endpoint users have installed FortiClient and are onboarded to FortiSASE with the invitation code.
  • FortiClient status is connected to FortiClient EMS Cloud.


EMS_connected.png

  1. On FortiSASE Portal, create a new endpoint profile for specific users under Configuration -> Endpoints -> Profiles -> Create.
    e.g. An endpoint profile named 'Anderson' for non-AD user groups is created.


anderson.png

 

  1. Under the endpoint profile, create the custom VPN tunnels (SSL or IPSec VPN) under  Connection -> VPN available to users'
    e.g. A custom SSL VPN tunnel for the remote gateway (10.92.99.44:10443) is configured.


custom sslvpn.png

  1. Ensure that the endpoint profile is not being overridden by other profiles for the users/user group. Managed endpoints of the assigned profile can be viewed under Profiles -> View Endpoints.

 

endpointss.png

 

  1. After configuring the custom VPN tunnels, users assigned with the created endpoint profile should receive the custom VPN tunnels after the next EMS telemetry sync.


3.png

 

vpn.png