Hi
Is there a way to provide a choice of profiles for sslvpn clients (or with a different method to access)?
For example, a user would have the possibility to connect either with split tunnelling or without it.
I think, it is possible if it was based on group membership, but the user would need to be in only group, and therefore would only have method available
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Try realms like in the cookbook. You don't have to have different groups to use realms. Each can use different auth method(group) and portal. We use them for a user to be in different facets of groups. But I don't see any reason they can't be the same group. Portals are the ones that decide split or no-split and what destinations to be able to reach for tunnel-mode.
This is the link to the cookbook:
[link]https://cookbook.fortinet.com/multi-realm-ssl-vpn/[/link]
Here's a post on my blog on realm and the function that it can offer.
http://socpuppet.blogspot.com/2017/05/fortigate-sslvpn-and-multiple-realms.html
Ken Felix
PCNSE
NSE
StrongSwan
Thanks guys. I will have a look. I did not know about realms and found out it was not available by default. Will have a go. Hopefully, it will not break the current live settings!
It wouldn't break existing non-realm SSL VPN. That's how we implemented a realm originally. Then eventually migrated to all realm set-up.
Or if you need to support multiple profile/depts/etc....... realms are the way to go ;)
Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.