Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tpfannes
New Contributor

Static IP For SSL VPN Users

All,

 

I have an application that requires my SSL VPN Clients to have the same (static) IP address when connecting via ssl VPN.  Is there anyway to accomplish this similar to using MAC Reservation in DHCP?  

5 REPLIES 5
gschmitt
Valued Contributor

I think you have to create seperate portals for all users.... How many users are we talking about?

ede_pfau

Source NAT might be easier. Clients need unique IP addresses for routing.

sNAT: in the policy "ssl.root" -> "internal", create an IP pool with just one address and check NAT, specify IP pool.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

Or craft a pool address for just that user. You can could use dhcp also but mac_addr reservation would be of no use ( it's a layer2 function )

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
tpfannes

gschmitt wrote:

I think you have to create seperate portals for all users.... How many users are we talking about?

Around 100 so SNAT or individual portals is out of the question.  Think I'm out of luck.

ede_pfau

Around 100 so SNAT or individual portals is out of the question.
No, on the contrary. Think about what I've proposed. It might well be the only way to achieve this.

What's so difficult in creating ONE IP pool??

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors