Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
D-hg
New Contributor III

Setup Forticlient as dialup Client

Hello,

 

I configured as the manual an IPsec Tunnel to be able to connect the remote clients to the LAN. I was thinking then to restrict the firewall rules (users can access to servers, others users no). But that seems to not working when I put a user group in source of the firewall rule. Is there a way to restrict the access of the LAN for some users o it will have access of all the infrastructure ?

In SSL it's possible to do it easily but don´t find a way in IPsec..

Many thanks

1 Solution
akanibek

 
Exactly, with IPSec VPN there is no possibility to restrict permissions with groups. 
 
Asset

View solution in original post

6 REPLIES 6
akanibek
Staff
Staff

Hey, 

you can get acquainted with the article below about differences of IPSec and SSL-VPN. 
Also, haven't you looked to the guide below?

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/559546/ssl-vpn-full-tunnel-for-remote-u...

 

Asset
D-hg
New Contributor III

Hello,

 

I configured both VPN in my FORTIGATE, I know that I can manage permissions with SSL, and was wondering if It was possible or not with IPsec (The IPsec is faster than SSL, that's why my question). 

 

The article is just to know how to configure a SSL VPN and I already did it, are you guessing that with IPsec the permissions are not possible?

akanibek

 
Exactly, with IPSec VPN there is no possibility to restrict permissions with groups. 
 
Asset
pjawalekar
Staff
Staff

Hi,
Thank you for your query, please be notified that in plain site to site vpn it is not possible to restrict the access based on user name or user group. However you can configure the dialup ipsec vpn or ssl vpn to achiev this.

Regards,

Pratik

 

 

asengar
Staff
Staff

Hi @D-hg 

 

Thanks for posting your query

 

You can restrict the access to the network by configuring the IPSEC dial up VPN

Kindly refer the below documents and check if it can help the requirement

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-group-based-firewall-policy-for-Dial...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-a-FortiGate-as-IPsec-VPN-...

@bhishek
D-hg
New Contributor III

Hello, When I try to put this conf I cannot connect with anyone.

 

Many thanks for your help

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors