Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Akbar_ali
New Contributor

how to authenticate using AD for web VPN SSl logged-in user and separate them ?

HI,

Cronavirus is spreading globally and now the scenario is work from home. i have fortigate 100D and i want to allow user to connect their PC using WEB VPN. i already setup tunnel mode but its require to have forticlient. is it possible to use WEB VPN and just specific user can see his remote desktop IP and can login using AD account.

here is the things that i need

[ol]
  • specific user using WEB VPN (i already setup) and see only his remote desktop
  • user should use their AD account to connect.[/ol]

    Kindly assist.

    Thanks

  • 1 REPLY 1
    lobstercreed
    Valued Contributor

    Hi Akbar,

     

    You'll need to set up an LDAP connection or use a RADIUS server (if you have one) to authenticate the users against AD.

     

    I have never had any luck getting web mode VPN to work, but to be honest I just haven't tried too hard since tunnel mode using FortiClient is so much easier and more reliable.  If it's at all possible to provide the users with FortiClient or instructions on how to install it and set it up (not hard) then I would recommend that. 

     

    You'll then want to set up policies from ssl.vpn to lan with each one specifying a source of the tunnel network and the user in question while the destination is that user's PC.  This would need to be done even if you tried to use web mode only.

     

    I happen to have some extra time off this next week so if you want remote help (for a very reasonable fee, DM me).

     

    Thanks - Daniel

    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors