Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
EasyDoesIT
New Contributor

Fortigate SSLVPN with DUO MFA - Can different AD groups be used for different FWP applied?

Im looking to determine if different AD security groups can be configured on DUO to allow a user logging in to the SSLVPN to get a different firewall policy depending on their AD group membership. I know you can restrict access with one security group but I'm looking to see if multiple AD groups can be configured in DUO. 
I found this, but it still only references one group.

security_group_dn

To further restrict access, specify the LDAP distinguished name (DN) of a security group that contains the users who should be able to log in as direct group members. Nested groups are not supported. Users who are not direct members of the specified group will not pass primary authentication. Example:

 

security_group_dn=CN=DuoVPNUsers,OU=Groups,DC=example,DC=com

 

Starting with Authentication Proxy v3.2.0, the security_group_dn may be the DN of an AD user's primarygroup. Prior versions do not support primary groups.

 

Best

4 REPLIES 4
Mrinmoy
Staff
Staff

You can call multiple AD groups in fortigate and applied them in firewall policy

Mrinmoy Purkayastha
dbu
Staff
Staff

Hi @EasyDoesIT ,
Have a look at the guide here how to create SSL VPN with multiple realms :

https://community.fortinet.com/t5/Blogs/Deploying-SSL-VPNs-Using-Multiple-Realms/ba-p/238145

 

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/724772/ssl-vpn-multi-realm

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
hbac
Staff
Staff

Hi @EasyDoesIT,

 

If you are using RADIUS authentication, you can refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-define-group-based-authorization/ta...

 

Regards,

EasyDoesIT
New Contributor

I have found a DUO help article:

https://help.duo.com/s/article/3162?language=en_US

Labels
Top Kudoed Authors