We have an HA pair of FortiGate 500E's. They are running 7.0.5
I have successfully configured SSO for our Split Tunnel portal and it is working. FortiClient successfully takes us to the identity provider which is JumpCloud and allows me to connect with the Split Tunnel access.
But we also have users that we want to use the Tunnel All portal. I have configured it the same way I did as the Split Tunnel but I think I need to somehow specify which one the user needs to connect to. And I am not sure how to do that specification. Does anyone have any ideas here?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You could technically configure authentication rules and match portals based on groups in SAML response. But it can get very complex and difficult to troubleshoot.
My recommendation is to create separate SSL VPN realms for your split and full portals. You can find a detailed guide here. The example uses Azure as SAML IdP, but the Fortigate and FortiClient configuration will be essentially the same.
Realms is exactly what I was looking for. Thank you!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.