Hi,
I have Fortegate 100F with OS 7.4.x
I configured SSO with EntraID successfully and login was working.
I have a questions.
Q) Can I use more than one entra id group for separate vpn portal and policy.
A user member of group A and assigned the portal A and apply policy A,
and B user member of group B and assigned the portal B and apply policy B
And I have in trouble
T) User can login was successfully with Entra ID, and connected.
But SSL VPN client didn't receive internal routing table, only DMZ routing table was received.
It add routing table in manually 'route -Add xxx -mask...' then it can be communicated.
Anyone have solution like issue, please help me.
Thank You.
Solved! Go to Solution.
Hi,
Yes you can setup multiple portal and different policy for entra ID group using object ID
Regarding 2nd issue check the split routing setup
Hi,
Yes you can setup multiple portal and different policy for entra ID group using object ID
Regarding 2nd issue check the split routing setup
Thank you for your reply.
While I check as your advice, I found something wrong.
User A is member of EntraID GroupA and user A is logon OK then I remove membership in EntraID, now user A have no VPN permission and he shouldn't login.
But user A can logon and user A member of the others group, in VPN logon monitoring screen.
User A have no membership of the others group.
Do I more set EntraID or Fortigate?
Please help me..
Hello,
The issue has been solved.
casue:
The group member setting of fortigate was set to only azure as set in sso, and the group UID was not added, so authority was granted to all azure users. :)
Now woking perfectly.
One more thing I found out is that, as you said, you can create multiple groups in entraid and use them, but it does not support more than one group. If a user is included in group A and group B, only one of the two is applied and the settings are granted, so in order to control the destination, you need to control it in the policy, and you should not use override in the vpn portal to limit the address.
User | Count |
---|---|
2588 | |
1380 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.