Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jan_1966
New Contributor

Using VPN users in Security policies

Hi,

 

I am new to fortigate and just configured Remote access VPN for FortiClient to our FortiGate cluster. I created Firewall rules for the IP Address pool to the internal network, however some rules I like to narrow down for specific VPN users.

 

I Have added 2 Ldap users to the Firewall which are also using FortiTokens for MFA.

 

 

For example I want only user1 to be able to access internet in the following configuration. Is it just a matter of adding User1 to the source of the rule?

 

edit "User1" set type ldap set two-factor fortitoken set fortitoken "xxxxxxxxxxxxxx" set email-to "user1@mail.com" set ldap-server "Ldap-server"

edit 245 set name "RA_Users Web Access" set uuid 13c77ac4-3ca4-51ea-d2bd-4dd6af20a26e set srcintf "RAVPN" set dstintf "Untrust" set srcaddr "RA_IP-pool" set dstaddr "all" set action accept set schedule "always" set service "ALL" set utm-status enable set logtraffic all set fsso disable set comments "RA Users Web Access policy" set av-profile "xxxxx" set webfilter-profile "xxxxxxxx" set ips-sensor "default" set ssl-ssh-profile "certificate-inspection" set nat enable

 

Many thanks,

 

Jan

2 REPLIES 2
makco10
Contributor II

Hello,

 

You need to add a group with that user selected in the VPN config:

 

https://kb.fortinet.com/kb/documentLink.do?externalID=FD36413

 

Regards.

Defend Your Enterprise Network With Fortigate Next Generation Firewall
Defend Your Enterprise Network With Fortigate Next Generation Firewall
Jan_1966

Thanks Makco10,

 

I'll have a look into that.

 

Jan

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors