- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
can i set Limit on a specific user to One SSL-VPN Connection at a Time.
Dear Concern,
I want to set a limit on a specific SSL-VPN user so that this user can establish multiple connections at the same time. For example, User A should be able to establish SSL-VPN connections from two different laptops at a time using FortiClient.
If I configure it via GUI: VPN > SSL-VPN Portals, edit the SSL-VPN Portal, and enable "Limit Users to One SSL-VPN Connection at a Time", this restriction applies to all users, preventing multiple connections for everyone. However, I want to remove this restriction only for a specific user while keeping it enabled for others.
How can I achieve this? Please share the configuration steps.
Waiting for your valuable response.
Solved! Go to Solution.
- Labels:
-
FortiClient
-
FortiGate
-
SSL-VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear All,
I found the solution to allow multiple SSL-VPN connections for a Specific User via GUI in FortiGate-201F (v7.6.2 build 3462).
Step 1: Create a New User Group (for the specific user)
- Log in to the FortiGate GUI.
- Navigate to: User & Authentication > User Groups
- Click Create New.
- Set Group Name: Multiple-SSLVPN-Users
- In the Members section, select the specific user (e.g., User_A).
- Click OK.
Step 2: Create a New SSL-VPN Portal (dedicated to the specific user)
- Go to: VPN > SSL-VPN Portals
- Click Create New.
- Set Portal Name: Multiple-Connections-Allowed
- Uncheck the option “Limit Users to One SSL-VPN Connection at a Time”.
- Configure other portal settings as required (e.g., tunnel mode, split tunneling, IP pools, bookmarks, etc.).
- Click OK.
Step 3: Update SSL-VPN Settings
- Navigate to: VPN > SSL-VPN Settings
- Scroll down to the Authentication/Portal Mapping section.
- Click Create New.
- Under Groups, select Multiple-SSLVPN-Users.
- Under Portal, select Multiple-Connections-Allowed.
- Click OK.
- Ensure that other users/groups are mapped to a default portal where “Limit Users to One SSL-VPN Connection at a Time” is enabled.
Final Step: Apply Configuration
- Click Apply on the SSL-VPN Settings page.
- Test the configuration:
- The specific user (User_A) should now be able to connect from multiple devices simultaneously.
- All other users will remain restricted to a single SSL-VPN session at a time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not aware of a way to configure this locally on the FortiGate for a specific user. You may be able to use a RADIUS server to allow this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Mirza_Asad2723 ,
Limit Users to One SSL-VPN Connection at a Time -- is an option that on Fortigate can be modified under the SSL VPN settings and has the effect for all of the users. There is no other option that you can do individually for each user on firewall, this option can be done probably on the authentication server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear All,
I found the solution to allow multiple SSL-VPN connections for a Specific User via GUI in FortiGate-201F (v7.6.2 build 3462).
Step 1: Create a New User Group (for the specific user)
- Log in to the FortiGate GUI.
- Navigate to: User & Authentication > User Groups
- Click Create New.
- Set Group Name: Multiple-SSLVPN-Users
- In the Members section, select the specific user (e.g., User_A).
- Click OK.
Step 2: Create a New SSL-VPN Portal (dedicated to the specific user)
- Go to: VPN > SSL-VPN Portals
- Click Create New.
- Set Portal Name: Multiple-Connections-Allowed
- Uncheck the option “Limit Users to One SSL-VPN Connection at a Time”.
- Configure other portal settings as required (e.g., tunnel mode, split tunneling, IP pools, bookmarks, etc.).
- Click OK.
Step 3: Update SSL-VPN Settings
- Navigate to: VPN > SSL-VPN Settings
- Scroll down to the Authentication/Portal Mapping section.
- Click Create New.
- Under Groups, select Multiple-SSLVPN-Users.
- Under Portal, select Multiple-Connections-Allowed.
- Click OK.
- Ensure that other users/groups are mapped to a default portal where “Limit Users to One SSL-VPN Connection at a Time” is enabled.
Final Step: Apply Configuration
- Click Apply on the SSL-VPN Settings page.
- Test the configuration:
- The specific user (User_A) should now be able to connect from multiple devices simultaneously.
- All other users will remain restricted to a single SSL-VPN session at a time.
