Hello! I want to configure FortiClients to connect to a FortiGate 100D using IPSEC VPN, but so that different users authenticate against different AD-servers. Which means I can' t use " Accept any peer ID" in Phase1 configuration, otherwise all dialup clients will fall into the first policy and/or VPN.
If I use Shrewsoft VPN Client, then it has been OK, some clients already authenticate and use the VPN, because in Shrew client there is a special place where to enter that common peer ID.
The manual says (fortigate-ipsec-50.pdf, page 45):
-------
To configure FortiClient - pre-shared key and peer ID
1. Start the FortiClient Endpoint Security application.
2. Go to VPN > Connections, select the existing configuration.
3. Select Advanced > Edit.
Auto Key phase 1 parameters Page 45 IPsec VPN for FortiOS 5.0
4. In the Preshared Key field, type the FortiGate password that belongs to the dialup client (for example, 1234546).
The user account password will be used as the preshared key.
5. Select Advanced.
6. Under Policy, select Config.
7. In the Local ID field, type the FortiGate user name that you assigned previously to the dialup
client (for example, FortiC1ient1).
8. Select OK to close all dialog boxes.
Configure all FortiClient dialup clients this way using unique preshared keys and local IDs.
-------
But there is no " Advanced" , nor " Advanced\Edit" , nor " Advanced\Policy" as suggested by this instruction. I just upgraded to FortiClient 5.2 but that menu didn' t appear (and Register to FortiGate button doesn' t work anymore). I would gladly use these if they were there. FortiClient is currently not registered to a FortiGate so it doesn' t have any policy set. My goal was to use one and the same peer ID for all people belonging to one and the same company and use Xauth+LDAP to authenticate them based on their AD credentials against their own AD-server.
I also thought, maybe I shall use " Accept per ID in dialup group" and select that Xauth group, but that group is not in the list for some unknown reason.
If there is somebody having faced this and solved it, it would be nice to know.