- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Multiple Fortigate Client VPN Profiles
Hi All,
Please forgive the fairly basic nature of this question!
Our organisation is migrating away from Meraki MX Firewalls and onto Fortigate - probably 80F's or 100F's at this stage. With Meraki, only a single IPSEC VPN profile / subnet can be assigned per device. I have been asked to ensure that the below checklist is possible with Fortigate, I would really appreciate any support you are able to offer!
- Multiple VPN profiles / subnets - with the ability to assign different security restrictions to the various different VPN user groups / profiles?
- 2FA / MFA support for client VPN's?
- The ability to integrate with AD / Radius and authenticate users via their domain credentials
Further to this any comments on whether we should be using client SSL or traditional IPSEC VPN's would also be appreciated - huge thanks in advance! ☺
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Nurse.
All the below 3 requirements are supported on the FortiGate firewall.
- Multiple VPN profiles / subnets - with the ability to assign different security restrictions to the various different VPN user groups / profiles.>>supported
- 2FA / MFA support for client VPN's.>>>Supported.
- The ability to integrate with AD / Radius and authenticate users via their domain credentials>>supported.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Nurse.
All the below 3 requirements are supported on the FortiGate firewall.
- Multiple VPN profiles / subnets - with the ability to assign different security restrictions to the various different VPN user groups / profiles.>>supported
- 2FA / MFA support for client VPN's.>>>Supported.
- The ability to integrate with AD / Radius and authenticate users via their domain credentials>>supported.
