Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Baptiste
Contributor II

Lock VPN SSL client config

Hello, I' m using SSL VPN Client (not forticlient, haven' t test FTC V5.2 yet), I Wonder if I could lock all settings on user config (IP, login & password) ? Thanks !

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
8 REPLIES 8
jorge9090
New Contributor

Hello, what do you mean by lock? You can make a vpn profile on the VPN Client with all the parameters (Name, IP, Port) so you just need to type in your user and password every time you want to connect to the VPN.
Baptiste
Contributor II

Hello, I know that but I have some strange users : they just have to input fortitoken code... so they edit the vpnssl session and change password with those crazy changing numbers... It' s too esay to click Connect and After input fortitoken code...

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
hklb
Contributor II

Hello, You can install forticlient, and push the configuration from fortigate (User & device - Forticlient Profiles) and in CLI : set forticlient-settings-lock disable set auto-vpn-when-off-net disable set client-log-when-on-net disable set forticlient-ui-options vpn set forticlient-advanced-cfg disable But it is a licensed feature.
jorge9090
New Contributor

hklb, does it work on the VPN SSL client or it has to be the full Forticlient software?
jorge9090
New Contributor

Oh ok, i see what you mean. I don' t think there is a way to lock the parameters on the VPN SSL client, maybe they could access to the vpn via browser so the portal just promp them the user/password box.
hklb
Contributor II

It work for the forticlient, but you don' t need to install the full forticlient. You have the possibility to install only the VPN component. But I tested just now, I don' t find the way to remember the user/password.. (Sorry, I was sure it was possible.. )
jorge9090
New Contributor

But can you edit the parameters (IP, Port, etc) on the Forticlient? i think that is what Baptiste is looking for.
hklb
Contributor II

You are not able to change the VPN configuration config forticlient-vpn-settings edit " test.toto.com" set type ssl set remote-gw " test.toto.com" set sslvpn-access-port 443 set sslvpn-require-certificate disable next end
Labels
Top Kudoed Authors