Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jolu_itsme
New Contributor

VPN policy deny access to certain group

Hey all, I have setup a secondary VPN subnet and secondary VPN user group. The idea behind this is to give external persons access to some of our devices/addresses but not to the whole domain. In order to accomplish this I have created the subnet and user group and then made a policy to enable routing to one of the addresses the users need access to. That part is working. However those users also have the ability to connect to all the other devices. I created a rule to deny those as well but that doesn't seem to help. 

 

These have access to everything VPN_Users1 VPN_Subnet1

 

These only need access to specific addresses

VPN_Users2 VPN_Subnet2 The rules: 

VPN_Subnet2 -> DeviceAddress accept

internal -> VPN_Subnet2 deny all

 

Does anybody have an idea how I can fix this? 

1 REPLY 1
seshuganesh
Staff
Staff

Hi Team,

 

Can you explain the configuration in detail:

Like which vpn you are using, please share the screenshot of confiuration.

If it is ssl vpn we need screenshots of ssl vpn settings, ssl vpn specific portal screenshot and firewall policy screenshot.

Please share it us.

Labels
Top Kudoed Authors