- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SSL-VPN Host-Check fpr Win-Server
Hello,
is there a chance to add a Host-Check for Win-Server to block them for VPN Connection?
Many thanks
TBC
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @TBC
Please issue the following command and retry to connect with Linux host once again:
config vpn ssl web portal
edit "portal name"
set skip-check-for-unsupported-os disable
end
This is to configure FortiGate in a way that OS check is mandatory, and do not skip OS version that FortiGate is unable to identify:
Kayzie Cheng
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there:
Can you please try the following? Is this what you are looking for?
Thank you,
Hope.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @TBC
If you are connecting to SSLVPN on FortiGate, you can restrict the specific OS version to connect. You may refer to the following guide:
Once you turn on the feature of OS check, technically all windows server would not be able to connect. That is because the Windows Server OS version do not match those in the list.
Kayzie Cheng
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you both so much! Both info have helped me further!
What surprises me a little is that when HostCheck is active, Linux systems can use the VPN client.
Is there also a corresponding possibility for Linux?
Many thanks
TBC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @TBC
Please issue the following command and retry to connect with Linux host once again:
config vpn ssl web portal
edit "portal name"
set skip-check-for-unsupported-os disable
end
This is to configure FortiGate in a way that OS check is mandatory, and do not skip OS version that FortiGate is unable to identify:
Kayzie Cheng
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Cheng,
perfect, that's exactly that what I looking for!!
Many many thanks!
Cheers TBC
