Hello,
In the case of an IPSEC dial up VPN, can you select a user group in "Destination" in fortigate latest version (7.6.3) firewall policy ? I can't seem to have it for either IPSEC dial up VPN or SSL VPN in my fortigate (7.4.3). I can choose a user group only for the source.
Thank you
Well the whole idea is to have one tunnel for a group that has sub groups, i.e one tunnel for all sub groups, and then choose in firewall policy rules to allow whatever you want using either source or destination. It seems from your answers you can't select a group in a destination. What it does, is in this case, you will end up allowing traffic to go to all the subnet (i.e all groups) when you would want it to go only to some specific group.
It seems like the only solution from what you all said is multilple tunnels.
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.