Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lasersailing2k3
New Contributor

Autoconnect IPSEC Entra AD

Hi

 

We are tying to setup the following: Autoconnect to IPsec VPN using Entra ID logon session information

 

https://docs.fortinet.com/document/forticlient/7.2.3/ems-administration-guide/396545/autoconnect-to-...

 

We have the Client configured in EMS and able to connected to the IPSEC VPN, but how can you then control which logged in users have access via firewalls policies?  I was thinking about using usergroups on firewall policies but this just doesnt seem to work, does any one have any experience of restricting the FW policies based on which users are in which groups in Entra??

 

Many Thanks

4 REPLIES 4
johnathan
Staff
Staff

You can make multiple User Groups in the Firewall, but when selecting the SAML server you have the option to specify a group ID that will correlate with a group ID in Azure. This is how you can match different Entra ID groups to different  Firewall Groups.
See: https://docs.fortinet.com/document/fortigate-public-cloud/7.6.0/azure-administration-guide/584456/co...

"Never trust a computer you can't throw out a window."
lasersailing2k3
New Contributor

Thanks but that is using SAML with SSL-VPN.  We are using always on IPSEC with Entra.

 

following this link to do the authentication is what we are using, but its just not playing ball.

 

https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/33053

 

Seeing constant certificate warnings when trying pass user traffic through the firewall policies.

johnathan

I have attached a screenshot of what I am referring to (group name is the group ID in Entra ID). This is on the Firewall Group itself.
I don't think the document you shared is applicable for our situation (we are VPN, that .document is for on-prem)

"Never trust a computer you can't throw out a window."
johnathan

Sorry, It didn't attach >_<

"Never trust a computer you can't throw out a window."
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors