Hello.
We have configured the FGT as an SSL VPN terminator, implementing posture/compliance controls with the FortiClient EMS without any issues.
To force clients to not "skip" the posture and connect to the VPN by downloading FortiClient Free (since doing this the EMS cannot enforce the client's posture), we added the command in the FGT:
config system global
set vpn-ems-sn-check enable
end
We tested this and it works fine.
The issue is that now we need a mixed environment: clients with posture and clients without posture (i.e., FortiClient Free and not connected to the EMS).
For this, the current solution doesn't work anymore...
Is there a way to do this granularly by SSL VPN portal or similar? From what I've seen, SSL VPN is for the entire FGT globally.
thank you
regards
Hello
You can use groups. Put users having FCT in a group and users with Free FCT in another group. Then create firewall rule with ZTNA tags and with first group as source. And other rule without ZTNA tags and with second group as source.
Hello AEK,
ok, with that they would be able to connect to the VPN right? but no access to internal resources...
I saw this link,and is more granular with ipsec it seams...
Thank you!
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.