Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hari-smf
New Contributor

SSLVPN Ldap user group in firewall is not working

HI Team,

 

We have recently implemented FortiGate 200G firewall to replaced SonicWALL. Will before used one of the feature is not working in FortiGate i will raise ticket support team and confirmed they it will work like you can post your new query our R & D team will check and update, if possible, to next release. 

 

Here with i have mentioned my Query: -

 

As per our company policy we have configured AD based internet policy both internal users and  sslvpn users.we have more than 15 internet policy used in firewall both LAN to WAN and same as SSLVPN to WAN. we have created a firewall group with point AD group for example "Mailonly-allowed". these group using to SSLVPN to Wan policy who are part of this group connecting sslvpn they get internet access only mail access and they get which of the service i have allowed that user for example - HTTP, HTTPS.

 

But here what is the challenge we have facing, In that Mailonly group all users not required to SSLVPN may be Five users want sslvpn access out of 50 users. so i can't add this hole group in "VPN settings" so that i have created one firewall group and member that 5 users and added to SSLVPN Settings and appropriate policy (to access http and https) They get internet already we have SSLVPN to WAN policy using "mailonly" group. but this scenario group mismatch sslvpn is not authenticating. so as of now we have given individual users both vpn setting and policy its clumsier and complicating to do more than 10 to 15 types sslvpn service and policies.

 

 

  

 

 

 

1 REPLY 1
funkylicious
SuperUser
SuperUser

hi,

in my opinion you are over-complicating things.

since you already have a AD group with 50 users listed in the sslvpn settings/fw rules , you shouldnt care if only 5 use it to connect it's up to them.

 

now, if you just want a granular AD group consisting of only 5 ppl you can create it then reference it in a group on FGT and then use it in sslvpn/fw rules by i would recommend using realms for it.

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors