Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mohammed_Omar
New Contributor

IPSEC Dial Up VPN and Firewall Policy Rule

Hello,

 

In the case of an IPSEC dial up VPN, can you select a user group in "Destination" in fortigate latest version (7.6.3) firewall policy ? I can't seem to have it for either IPSEC dial up VPN or SSL VPN in my fortigate (7.4.3). I can choose a user group only for the source.

 

Thank you

10 REPLIES 10
Mohammed_Omar
New Contributor

Well the whole idea is to have one tunnel for a group that has sub groups, i.e one tunnel for all sub groups, and then choose in firewall policy rules to allow whatever you want using either source or destination. It seems from your answers you can't select a group in a destination. What it does, is in this case, you will end up allowing traffic to go to all the subnet (i.e all groups) when you would want it to go only to some specific group.

 

It seems like the only solution from what you all said is multilple tunnels.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors