Hi, all.
I'm new to Fortinet, having worked with other brands up til now.
I'm trying to get a new FortiGate 101F up and running, and I am now configuring IPSec tunneling using the FortiClient.
Is there a way to set access lists (network interface/subnets) based on user or user group? Can't seem to find any documentation on this, and unclear how this would be supported based on what I see when I configure the policy.
Thanks,
Chocolate Eater
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Once you switched to "inherit from policy", you need to make sure that any and all groups you want to be able to log into the VPN are listed in an active firewall policy in the tunnel->something direction.
If you're doing XAUTH or EAP authentication:
1, Leave the XAUTH/EAP group in phase1 configuration empty (CLI) or set it to "inherit from policy" (GUI).
2, Add the relevant group(s) in the firewall policies for <tunnel> -> <any desirable egress interface> policies.
=> As a result, the FortiGate will remember the users groups learned during IPsec authentication, and they can then be utilized to control access through policies.
Hi, pminarik.
It makes sence what you're saying, but when I set to "Inherit from policy" in XAUTH, I get an authentication failure. Which also makes sence, since it has no user groups to authenticate against.
But I guess I'm missing something....?
Once you switched to "inherit from policy", you need to make sure that any and all groups you want to be able to log into the VPN are listed in an active firewall policy in the tunnel->something direction.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.