Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
domnik968
New Contributor

FortiGate IPsec VPN for users

Hi everyone.

I am just trying to find out what everyone is doing regarding moving from SSL VPN to IPSEC VPN, what are you putting in place that is potentially free as safeguards and best practice methods.

Geo - location - restrict where users can SSLVPN from.
SAML - with 2FA auth.

Others?

Thanks in advance.

router login 192.168.l.l
2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Domnik

Regarding IPsec GeoIP restriction, here's how you can do:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restrict-IPSec-VPN-access-to-certain-count...

Hope it helps.

AEK
AEK
kaman
Staff
Staff

Hi Domnik,

 

You can follow the documents below regarding SAML-based authentication for FortiClient remote access dialup IPsec VPN clients:

 

https://docs.fortinet.com/document/fortigate/7.2.0/new-features/951346/saml-based-authentication-for...


https://docs.fortinet.com/document/forticlient/7.2.0/new-features/712604/ipsec-vpn-saml-based-authen...


Regards,
Aman

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors