Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Albimatta
New Contributor II

VPN IPSEC Dialup Connection IKE v2

Hello Guys,

I have two questions about the Ike V2 IPSEC DIalup Connection.

 

I want to configure in my enviroment (two fortigate 100F HA) like 150 dialup external connection. I have setup an IPSEC Tunnel (IkeV2) and set policy correctly.

 

I created the users locally (without any Proxy or RADIUS) and inserted in a group.

 

The VPN works fine but i have two questions:

- Is binding set in the IPSEC configuration the authusrgrp? because i haven't set and i won't set because if i set, every time thast the people connect appear when the people search a local ip for example, the Fortigate Auth page, and for us isn't necessary. So if i unset that is an error?

 

-  Ikev2 works fine with the local user (i enabled the EAP)? because i haven't any other type of authentication

 

Thank you so much

1 Solution
hbac

Hi @Albimatta,

 

Group should not be specified in the firewall policy. You can specify it under IPsec phase1-interface. 

 

Regards, 

View solution in original post

10 REPLIES 10
Yurisk
SuperUser
SuperUser

Well, in that case I would classify it as a bug and if you have Support active for this Fortigate, you could open a ticket with Fortinet TAC. As per configuration it should not be happening (provided you don't use User Groups in rules as well). 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors