Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
PaulWT
New Contributor

IPSec VPN to different internal interfaces

I've inherited a FortiGate 60F running 7.6.1. This is my first exposure to Fortigate as previously its's been Cisco Firepower and Palo Alto.

 

It currently has an IPSEC VPN allowing users access to one of the internal interfaces. Auth is currently carried out via LDAP. 

 

Is it possible to allow access to a different internal interface as the same time using a different credentials?

 

If so how?

3 REPLIES 3
dingjerry_FTNT

Hi @PaulWT ,

 

First of all, what type of IPSec VPN is it?  Site to site? Dial up?

Regards,

Jerry
PaulWT

It's a Dial Up

dingjerry_FTNT

Hi @PaulWT ,

 

For Dialup IPSec VPN, the user authentication is done in Phase 1. 

 

So I don't think that you can split the users for traffic control if using one dial-up IPSec VPN.

 

A workaround is to use multiple dial-up IPSec VPN tunnels with different peer IDs, in Interface mode.

 

Then you can create different firewall policies with those different IPSec VPN tunnels to control the traffic flow.

 

Here is the article on how to select one dial-up IPsec VPN tunnel with peer IDs on FGT:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-Peer-IDs-to-select-an-IPsec-dia...

Regards,

Jerry
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors