Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sined1701
New Contributor

Create a rule for Geolocation exclusion for some user

Hi everyone, I would like to create an Active Directory group so we can add user in it, and this group will be exclude for the Geolocalisation rules in Fortigate for the VPN connection.  Example: we block all country except USA and CAN. If someone goes in vacation in EUROPE, He can use his VPN if part of the group in AD mentionned before.

 

Can this be done ? thks for all your help.

 

DT

FortiGate #VPN

 

Denis T
Denis T
1 REPLY 1
hbac
Staff
Staff

Hi @sined1701,

 

You cannot use user group as source for "Limit access to specific hosts" or "local-in policies". 

 

Regards, 

Labels
Top Kudoed Authors