Hi,
I have a FortiGate FGT200F running 7.2 with a VPN setup to authenticate with SAML Entra (Azure), Its will working well but I am wanting to give the VPN users different Web Filter policies base on their Entra group they authenticated with. How would I configure outgoing ssl.root -> virtual-wan-link firewall policies base on the users group.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello julianhaines,
You may need to configure SSLVPN Realms to associate the VPN user's in your different webfilter firewall policies. https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/724772/ssl-vpn-multi-realm
Hello,
You need to create multiple User Groups on Fortigate, add Azure (SAML) Remote Server and specify Azure/Entra Group ID.
After that configure SSL VPN Authentication / Portal Rule.
Then create firewall policy per user group and incorporate specific Web Filter Profile per User Group.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1091 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.