Hi all, I need to allow 3 people access from SSL VPN to a few servers in the DMZ. Is user based policies possible and if so, what do I need in order to make that work? We do have RADIUS authentication against Active Directory set up for SSL VPN. We also have a SSL_VPN_USERS user group which has group type firewall and has the RADIUS server as member. I figured a user based policy might be better than a IP/Computer based one in case we change device.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
hm since the FGT doesn't know your users I don't think you can do user based. But you might be able to use radius groups in policies.
If anyone knows better please don't hesitate to correct me though ;)
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Yes this should work since you are performing active authentication with SSL VPN.
Yes you can achieve the same by configuring user in source address and configure destination as your DMZ server. once user logged in to SSL VPN user will be mapped to ip and if packet comes firewall will be able to take action on basis of user policy
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.