Hello All, I have an issue about Dialup IPsec VPN user management, I am wondering if I can setup one IPsec VPN with multiple dialup user account in one user group. And with different account have different permission to access LAN ? Or is it possible to setup multiple dialup IPsec VPN Tunnel with one WAN interface ? Any help and support is appreciated
Should both be possible some way ;)
basically you can create many dial up tunnels on one wan (the bandwith is the limit ;) ).
And you cannot have more then 1000 concurrent users (i.e. dialled in at the same time) on one dial up vpn.
If you do this way you should use local/remote id to unify the tunnel to make sure the FGT choses the right one upon client dialling in.
you can create a group and add users to it and then use the group for auth in ipsec.
And at least from FortiOS 6.2 on you should be able to use users as objects in policies.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.