Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
v20100
New Contributor III

Choice of SSLVPN profile

Hi

Is there a way to provide a choice of profiles for sslvpn clients (or with a different method to access)?

 

For example, a user would have the possibility to connect either with split tunnelling or without it.

 

I think, it is possible if it was based on group membership, but the user would need to be in only group, and therefore would only have method available

 

Thanks

6 REPLIES 6
Toshi_Esumi
Esteemed Contributor III

Try realms like in the cookbook. You don't have to have different groups to use realms. Each can use different auth method(group) and portal. We use them for a user to be in different facets of groups. But I don't see any reason they can't be the same group. Portals are the ones that decide split or no-split and what destinations to be able to reach for tunnel-mode.

Toshi_Esumi
Esteemed Contributor III

This is the link to the cookbook:

[link]https://cookbook.fortinet.com/multi-realm-ssl-vpn/[/link]

emnoc
Esteemed Contributor III

Here's a post on my blog on realm  and the function that it can offer.

 

  http://socpuppet.blogspot.com/2017/05/fortigate-sslvpn-and-multiple-realms.html

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
v20100
New Contributor III

Thanks guys. I will have a look. I did not know about realms and found out it was not available by default. Will have a go. Hopefully, it will not break the current live settings!

Toshi_Esumi
Esteemed Contributor III

It wouldn't break existing non-realm SSL VPN. That's how we implemented a realm originally. Then eventually migrated to all realm set-up.

emnoc
Esteemed Contributor III

Or if you  need to  support multiple profile/depts/etc.......  realms are the way to go ;)

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors