Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Anne
New Contributor III

Forticlient IPSec VPN

Hi there, Whats the best way to setup Forticlient IPSec vpn with the following requirements: 1) AD authetication 2) Some users have access to 10.1.1.0/24 subnet only 3) Some users have access to 10.1.2.0/24 subnet only 4) Some users from 2 & 3(listed above) have access to both the subnets. Thanks in advance Anne
1 REPLY 1
Warren_Olson_FTNT

Hey Anne, I don' t believe you' re going to be able to use LDAP/AD with IPSEC vpn. In 4.x there was an option to specify an authusrgrp via CLI where you could choose a remote LDAP server but I don' t see it in 5. Here' s some info from the Authentication handbook guide for IPSEC: " Authenticating IPsec VPN users An IPsec VPN can be configured to accept connections from multiple dynamically addressed peers. You would do this to enable employees to connect to the corporate network while traveling or from home. On a FortiGate unit, you create this configuration by setting the Remote Gateway to Dialup User. It is possible to have an IPsec VPN in which re mote peer devices authenticate using a common preshared key or a certificate, but there is no attempt to identify the user at the remote peer. To add user authentication, you can do one of the following: • require a unique preshared key for each peer • require a unique peer ID for each peer • require a unique peer certificate for each peer • require additional user authentication (XAuth) The peer ID is a text string configured on the peer device. On a FortiGate peer or FortiClient Endpoint Security peer, the peer ID provided to the remote peer is called the Local ID. "
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors