Hi, I am trying to setup ipv4 policy for specific user with less limitations. I created user from LDAP , even group synced from LDAP , then when I am trying to set that user or group in the source its not letting me to Apply, its asking to add
"One address, address group, or Internet service is required" as a source , but my user is getting dynamic ip address by connecting with ssl vpn. And i cant select IP address for this user. Anyone can advice how this can be set up? FGT200, version 6.0.10 Thank youNominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
In version 6.4.6 you can configure the policy with source network of SSLVPN tunnel and user or group, in destination anyone else. It works.
As alluded to by ac, you DO have to use a source address. While the user's IP might be dynamic, I'm sure you can predict the range it will be in, so you can define an address object of the entire DHCP range and use that in the policy. Then it will match both the address in X range and the user abc. It will ignore other users in X range because it is AND logic.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.