Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
shrry8
New Contributor

Allow Blocked Applications to AD Users

Hello, I have blocked all the unwanted applications from Fortinet 100D. But for some AD users I have to allow those applications for them. But its always opened for all users not for 2-3 users. How can I do it Secondly, i want only one AD group to be permitted for connecting over VPN. Let me know how can I do it.
2 REPLIES 2
Devendra_Palan
New Contributor

Hi shrry8, To allow the applications you must create policy with user identity and apply the necessary UTM profiles for the perticular group. For VPN, Firstly you have to integrate you AD with firewall & create the group. then select under Phase 1 XAuth as server and select the respective group. Based on group membership user will get access to VPN.
rwpatterson
Valued Contributor III

Welcome to the forums. Similar to what Devendra stated, create an AD group of the users, and then craft a policy allowing that group out to the resource. As far as SSL VPN, I connect to the AD structure using LDAP, this way I can assign different AD groups to different areas in the network based on their AD group membership. Hope that helps.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors