Ok so here is my issue:
We have users who are connecting from home/other remote locations over the SSL VPN tunnel.
Inside Policy&Objects>Objects>Addresses there is an range named SSL_VPN that is 192.168.10.4-192.168.10.63 (any interface)
The SSL settings from VPN>SSL>Settings have the SSL_VPN object in the IP Ranges field
It doesn't matter to me which IP address is reserved, but I need to have one of those addresses reserved for a specific user. Whenever this user connects to the SSL VPN he needs to get the same IP address.
I can see how to do this with dhcp reservations for the physical interfaces, but I cannot see how to do this for the SSL VPN connection.
Any help you can give is greatly appreciated!
You need to create a separate IP pool to have only one IP, say 192.168.10.4(you need to adjust the original pool not to have this IP), and bind it to SSL portal config (if v5.2). This means you need to create another portal separated from the other users' and specify it in the policy.
You are correct this is v5.2
So I have modified the original object to be 192.168.10.4-63 and created a new object for 192.168.10.3 named Remote_Laptop.
I have also created a new portal, named Remote Laptop, but its reference count is 0. I bind the address, is this a CLI only sort of thing?
Thanks for the help!
I don't know how you authenticate those users but you need to have a usergroup for the single host and another for all the others if local authentication. Then one usergroup and one portal needs to be bound together under SSL Settings. You need to have two sets. That's where the portals are referred with 5.2.
Why can't you just use identity-basd fwpolicy? Who cares what the user ipv4/v6 address is. Just ID the user and allow him/her access based on identity. Base a group for that user(s) and authenticate him locally or better yet remotely ( i.e LDAP ) and allow the fw to allow traffic base on the user-ID.
ken
PCNSE
NSE
StrongSwan
Yes, much more logical with id based policy for SSL VPN
If you're using a radius server, you can use this feature for reserve IP address to users:
In 5.4 are commands little changed...
config vpn ssl web portal
edit "PORTAL"
set ip-mode user-group
NSE8 #3111
I didn't mean actul "ip pool" but an address object. Sorry.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.