Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MBR
New Contributor III

IOS per-app VPN compatibility with FortiGate VPN

Hi,

 

Does anyone know if Fortigate VPNs can be used for the IOS per-app VPN functionality deployed using Airwatch, Intune, XenMobile etc?

 

For example intune doesn't mention Fortigate as supported connection type:

https://docs.microsoft.com/en-us/intune/vpn-settings-ios

 

Thanks.

 

- MBR -

NSE1, NSE2, NSE3

FGT60D/E, FWF60D/E, FGT200D

- MBR - NSE1, NSE2, NSE3 FGT60D/E, FWF60D/E, FGT200D
6 REPLIES 6
bommi
Contributor III

Hi,

 

this is not possible with fortinets ssl-vpn.

 

Regards

bommi

NSE 4/5/7

NSE 4/5/7
ispcolohost

Apple's Configurator 2 guide makes it sound like additional per-app VPN types can be defined as a custom config?  

 

For other SSL VPN solutions, contact your vendor and ask if they have an app in the App Store. If they do, choose Custom SSL from the Connection Type pop-up menu, then enter the configuration information provided by the vendor. Make sure the Identifier field matches the identifier specified by your vendor’s VPN app and is in reverse DNS format (for example, com.example.myvpn). Your users must install both the vendor’s app and the configuration profile to connect to your network.

 

Will this definitely not work with FortiClient?  The 5.4.1 ios guide mentions FortiClient having an identifier of com.fortinet.forticlient and support for split tunnel ssl-based vpn.  I was hoping to use this same functionality so I can get one ios app to an internal server but not touch anything else.

bommi

Hi,

 

you have two options:

 

1. Default route all traffic through the forticlient vpn tunnel.

2. Split tunnel specific routes through the forticlient vpn tunnel.

 

Routing specific per-App traffic through the tunnel is not supported.

 

You could ask your local SE to submit an Feature Request or search for an existing one.

 

Best Regards

bommi

NSE 4/5/7

NSE 4/5/7
fsfetea
New Contributor

Hello,

 

So is there an Identifier for the MacOs built-in Vpn client from Forti? Example: net.openvpn.OpenVPN-Connect.vpnplugin http://www.codingmerc.com/blog/ios-vpn-on-demand-profile-with-openvpn/ If openVpn has one does Forti also have one ?

 

I found something(com.fortinet.forticlient) for web filtering but I am not sure if this is the right one

https://docs.fortinet.com/uploaded/files/4617/forticlient-ios-6.0-user-guide.pdf

 

Regards

nchayrigues
New Contributor

hi, i have the same problem .....

i think we use Apple configurator ..

kboutelle
New Contributor

I have this question specifically about Intune. 

Labels
Top Kudoed Authors