Hello ,
I’m planning to change My current setup from SSL-VPN to IPsec remote access, but I have a few questions first.
How can we handle geolocation restrictions, MAC-address allow/deny, and host checks when using IPsec? For example, will geolocation and MAC binding be enforced only through the firewall policy, or is there a different approach for IPsec remote connections?
Thank you.
Hi Abdelrahman
In IPsec you should be able to filter on GeoIP with local-in policy.
To restrict on some MAC addresses then this tech tip may help (I didn't test it though).
But if you are looking for a serious host authentication and compliance solution then ZTNA should be your one of the best solutions (licensed version of FortiClient).
| User | Count |
|---|---|
| 2808 | |
| 1426 | |
| 812 | |
| 764 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.