Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AbdelrahmanElsokary

Transfer From SSL Vpn to ipsec remote

Hello ,

I’m planning to change My current setup from SSL-VPN to IPsec remote access, but I have a few questions first.

How can we handle geolocation restrictions, MAC-address allow/deny, and host checks when using IPsec? For example, will geolocation and MAC binding be enforced only through the firewall policy, or is there a different approach for IPsec remote connections?

Thank you.

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Abdelrahman

In IPsec you should be able to filter on GeoIP with local-in policy.

To restrict on some MAC addresses then this tech tip may help (I didn't test it though).

https://community.fortinet.com/t5/FortiGate/Technical-Note-Configure-IPsec-VPN-with-XAUTH-authentica...

But if you are looking for a serious host authentication and compliance solution then ZTNA should be your one of the best solutions (licensed version of FortiClient).

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors