Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mbilli
New Contributor

Push Fortigate VPN to Windows 11 builtin client using Intune

Has anyone managed to get this working? I've tried L2TP and IKEv2 options in Intune but I can't see an option to provide a PSK to Intune and I'm not sure the EAP XML/cert option will work here.

Speed Test https://vidmate.bid/
3 REPLIES 3
Jean-Philippe_P
Moderator
Moderator

Hello mbilli, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Regards,
Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Regards,
Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello mbilli,

 

I found this solution. Can you tell me if it works, please?

 

To configure a FortiGate VPN on a Windows 11 built-in client using Intune, follow these steps:

 

  1. Configure VPN Profile in Intune:
    - Go to the Microsoft Endpoint Manager admin center.
    - Navigate to Devices >Configuration profiles > Create profile.
    - Select Windows 10 and later as the platform.
    - Choose Templates > VPN.

  2. Select VPN Type:
    - For L2TP over IPSec, select L2TP.
    - For IKEv2, select IKEv2.

  3. Configure VPN Settings:
    - Enter the Connection name and Server name or address.
    - For L2TP, you will need to configure the Pre-shared key (PSK). Unfortunately, Intune does not directly support entering a PSK for L2TP. You may need to use a custom XML configuration for this.

  4. Custom XML for PSK: If using L2TP, you may need to create a custom XML to include the PSK. This involves creating an XML file with the necessary VPN configuration and uploading it to Intune.

  5. Certificate Configuration: If using IKEv2 with certificates, ensure that the client certificates are deployed to the Windows 11 devices. This can be done through Intune by deploying a certificate profile.

  6. Deploy the Profile: Assign the VPN profile to the appropriate user or device groups in Intune.

  7. Testing: Ensure that the VPN connection can be established from a Windows 11 device using the built-in VPN client.

 

If you encounter issues with the EAP XML/cert option, ensure that the certificates are correctly installed and trusted on the client devices. Additionally, verify that the FortiGate is configured to accept the authentication method you are using.

If further assistance is needed, consider consulting Fortinet support or Microsoft support for specific guidance on using Intune with FortiGate VPNs.

Regards,
Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors