Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zorro
New Contributor

VPN and Always-UP

Hi

 

I would like to configure Fortigate for always-up VPN connectivity like Direct Access with the VPN being initiated before the user has logged on to the laptop. Either secured by a valid certificate issued individually to each machine from our internal CA (we already issue certs for corporate wireless access so using the same computer cert would be helpful) or using Windows credentials + eventually some form of second factor. Of course it should be secure, but also convenient for the end user. Does anyone know if this kind of scenario is supported?

 

And if yes, would you go down that road? I mean reagrding evntual issues with forticlient and installation of the same on Win10 machines.

 

TIA, Zoran

4 REPLIES 4
Fullmoon
Contributor III

Fortigate Newbie
zorro
New Contributor

Hi

 

Tnx for quick answer, @Fullmoon!

 

I've seen that video, but the focus there is mostly on how do you configure xml profile, not is it possible to use machine certificate instead of AD username/password.

 

I am also wondering does this need additional licenses on Fortigate?

 

BR

Zoran

dstrausser
New Contributor

Hey Zoran,

 

I am actually in the same boat as you are and I also cannot seem to find any useful information in the guides or forums for this.

chrisparker

Did anyone get this resolved? I'm looking for the same info. Any help would be appreciated.

Labels
Top Kudoed Authors