Hi,
I've inherited a client that has a Fortigate 61E firewall and have to set up a VPN user. I've been trying to follow the below document but get a little lost by the time it gets to the IPv4 Policy.
https://blog.vpntracker.com/how-to-configure-vpn-for-a-fortinet-fortigate-firewall/
The really weird thing is, they have one VPN user already setup who can successfully dial in to the LAN using Forticlient from his home computer.. I can find no trace of a VPN, a user or any settings related to a configuration that allows this user to VPN through it.
Any help appreciated.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
There are two types of VPNs you can use, IPsec and SSL based. SSL VPNs are the preferred and easiest to set up, also are better to adapt to the network limitations (internet).
There are two types of VPNs you can use, IPsec and SSL based. SSL VPNs are the preferred and easiest to set up, also are better to adapt to the network limitations (internet).
I looked at all these settings before, but after your post, I had a closer look and suddenly understood how it all worked.
Cheers.
Dear @RobNS
To double check and verify please follow the below steps:
This method lets you identify which user is currently connected to the FortiGate VPN.
Hi @RobNS ,
Assuming you have already created a local user following the guide you have shared, it will be much better if you can assign that user to a user group. The reason for this is that when you have new SSL-VPN users to add in, you simply just need to assign them to the SSL-VPN user group and no more additional configuration to do.
After that, Navigate to SSL-VPN Settings -> Authentication/Portal Mapping and set the user group with the portal you would like to assign for them. Do not forget to click 'Apply' to commit the changes.
Lastly, you'll need to add the new user/user group to the firewall policy so that they can access internal resources. You can just use the search bar and find "ssl.root" which is the SSL-VPN tunnel interface. It is important to take note that under the source address, you need to put up both the IP address and the User/User Group in order for it to work.
Ref : https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/307303/ssl-vpn-split-tunnel-...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.