I've inherited a FortiGate 60F running 7.6.1. This is my first exposure to Fortigate as previously its's been Cisco Firepower and Palo Alto.
It currently has an IPSEC VPN allowing users access to one of the internal interfaces. Auth is currently carried out via LDAP.
Is it possible to allow access to a different internal interface as the same time using a different credentials?
If so how?
It's a Dial Up
Hi @PaulWT ,
For Dialup IPSec VPN, the user authentication is done in Phase 1.
So I don't think that you can split the users for traffic control if using one dial-up IPSec VPN.
A workaround is to use multiple dial-up IPSec VPN tunnels with different peer IDs, in Interface mode.
Then you can create different firewall policies with those different IPSec VPN tunnels to control the traffic flow.
Here is the article on how to select one dial-up IPsec VPN tunnel with peer IDs on FGT:
User | Count |
---|---|
2555 | |
1356 | |
795 | |
648 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.