Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BruceLiu
New Contributor

[Fortigate] Support of Security Posture Check via Free SSL VPN

Dear Team,

 

I would like to understand the SSL VPN connectivity features of the latest version of Fortigate combined with FortiClient. In scenarios without EMS integration, is security posture checking still supported?

As shown in the figure below:

forticlient.png
Bruce Liu

 

 
 
1 Solution
kaman
Staff
Staff

Hi BruceLiu,

Security posture checking is supported in the latest version of FortiGate combined with FortiClient for SSL VPN connectivity. You can configure host checking rules on the FortiGate to allow or deny access to the SSL VPN based on specific requirements. FortiClient will receive these host-checking rules from the FortiGate during the initial connection stage and assess if it complies with the rules before establishing the VPN connection.

Please refer to the documentation for more details on configuring OS and host check for SSL VPN connections: -

FortiGate-powered host check for free VPN client 7.0.3: [Link](https://docs.fortinet.com/document/forticlient/7.0.0/new-features/651315/fortigate-powered-host-chec...) - Configuring OS and host check: [Link]

(https://docs.fortinet.com/document/fortigate/latest/administration-guide/32970/configuring-os-and-ho...)

View solution in original post

2 REPLIES 2
kaman
Staff
Staff

Hi BruceLiu,

Security posture checking is supported in the latest version of FortiGate combined with FortiClient for SSL VPN connectivity. You can configure host checking rules on the FortiGate to allow or deny access to the SSL VPN based on specific requirements. FortiClient will receive these host-checking rules from the FortiGate during the initial connection stage and assess if it complies with the rules before establishing the VPN connection.

Please refer to the documentation for more details on configuring OS and host check for SSL VPN connections: -

FortiGate-powered host check for free VPN client 7.0.3: [Link](https://docs.fortinet.com/document/forticlient/7.0.0/new-features/651315/fortigate-powered-host-chec...) - Configuring OS and host check: [Link]

(https://docs.fortinet.com/document/fortigate/latest/administration-guide/32970/configuring-os-and-ho...)

BruceLiu
New Contributor

Dear Kaman,

That sounds great.

I happen to have a Fortigate 60E on hand, and I will try using it.

If I encounter any issues, I will consult you.

Regards,

Bruce Liu

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors