Hello,
In the case of an IPSEC dial up VPN, can you select a user group in "Destination" in fortigate latest version (7.6.3) firewall policy ? I can't seem to have it for either IPSEC dial up VPN or SSL VPN in my fortigate (7.4.3). I can choose a user group only for the source.
Thank you
you should be able to choose the group that is used for ipsec or sslvpn where the interface for ipsec or sslvpn is used.
if it's used as a source interface, then as a source and viceversa.
Sorry but in the case of a destination, i cant (i can only choose from address and service, no "user") even if the interface is the correct one.
for destination, it would make sense for the user to not be required only the IP address.
No, you cannot, neither in 7.6.3 nor in any FortOS version, and never could. Which means you are trying to achieve some goal in a wrong way, why would you need User Group as the destination? Tell us the final result you are trying to achieve.
Well if you have one IPSEC tunnel for a group that is formed by subgroups, you would like to filter in policy rules based on source as much as based on destination. for example :
IPSEC tunnel subnet of Big group A.
Group A contains small groups B and C.
If you want to add a policy rule allowing from IPSEC subnet group A to IPSEC subnet group A you cant because in the destination part there is no choosing user group.
Then split the policy into multiple ones, using group B in the source field. This makes the policy specific to this usergroup.
Created on 05-25-2025 09:46 PM Edited on 05-25-2025 09:46 PM
What @ede_pfau said - you can separate users into groups:
Then you have two independent IPSEc tunnel interfaces with separate user groups behind each, and now you can create security rules as between any networks behind FGT as usual. Still, you won't be able to use user groups in destination.
Hi team,
only in the source you can choose user group
-Naveen
Yes, I remembered that if I change something on the Tunnel side on FG, I should also change it in the same way on FortiClient. What surprised me the most was when I changed from IKEv1 Aggressive to IKEv2 there were no logs on the FortiGate side. It was as if there was no connection between my computer and FortiGate at all.
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.