Can I just flip the switch on IPSec XAUTH² to 'inherit from policy' and use the same rules as SSL-VPN, where you have to specify a Source and User/Group?
Last time I tried this, the FortiGate acted as a MITM for IPSec users and redirected HTTPS³ to its own IP, causing a certificate error. I had to roll back without investigating further.
FortiGate 200F 7.2.11
² XAUTH is set to a group containing a remote group which is a radius of our 2FA token.
³Split Tunnel, so not all HTTPS requests, only the ones where a FW rule was hit.
Solved! Go to Solution.
To merge IPsec-VPN and SSL-VPN into a common VPN zone using a third-party RADIUS server for two-factor authentication (2FA) on a FortiGate:
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Thanks,
To merge IPsec-VPN and SSL-VPN into a common VPN zone using a third-party RADIUS server for two-factor authentication (2FA) on a FortiGate:
User | Count |
---|---|
2570 | |
1362 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.