Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dan_Smith
New Contributor

FortiClient Always on VPN and Certificates

Hi, I' m new to the Fortinet Product range and am looking at VPN solutions for my company. Ideally what I would like to achieve is always on connectivity like Direct Access with the VPN being initiated before the user has logged on to the laptop secured by a valid certificate issued individually to each machine from our internal CA (we already issue certs for corporate wireless access so using the same computer cert would be helpful). Does anyone know if this kind of scenario is supported? I can' t seem to find much documentation on the always on VPN and on certificate configuration for forticlient but maybe I' m looking in the wrong places? Any advice or assistance on this would be helpful. Thanks Dan
3 REPLIES 3
Chris_Lin_FTNT

FortiClient supports always-on VPN for both SSL and IPSec. As to certificate, IPSec supports using certificate (X.509), without using user name and password as authentication (whereas SSL always requires user name). So you also want VPN to be connected before user logon windows?
Dan_Smith
New Contributor

Hi Chris, Yes ideally, in a similar way to Direct Access such that if the user is inside the corporate environment the VPN is disabled but outside the VPN is auto initiated. So we get the benefits of a DirectAccess style solution but with out the requirement for additional kit/servers. I assume you can use a split tunnel to save on traversing into and back out of the environment for internet traffic but still have browsing history sent back to the FortiAnalyzer and policy updates pushed down to the client from the Fortigate? Dan
Chris_Lin_FTNT

Hi, Dan, I think it' s pretty much do-able with FortiClient auto-connect and always-up feature. auto-connect will try to establish VPN once user logon Windows. Although FortiClient cannot tell whether it' s inside or outside corporate network, FortiGate VPN policy can be configured to only allow outside connections. So even FortiClient always try to connect when inside corporate network, it basically won' t affect normal usage. If your Windows has joined the domain, you can also enable VPN before logon. Chris
Labels
Top Kudoed Authors