Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
schofjosh
New Contributor

Portal access based on machine

Looking for advice on how to setup portal access based on machine.  My scenario is we currently have two portals.  One portal has full network access, and the other portal has only RDP access to the network.  The full access portal is for users that have company laptops and need full access to email, CIFS shares, etc.  The RDP only portal is for users that have physical desktops and only need to remote to the machine from their home computer.  My issue is that some of the users with laptops will occasionally leave their laptops at the office and then remote into their laptop from a home computer.  The issue is that when the laptop users connect to the SSL vpn from their home machine, they are getting full access to the network and thus opening the network up to vulnerabilities. I know you can lock down portals to specific MAC addresses, which seems like a nightmare to manage.  My ideal scenario would be to lock down the full access portal to the company laptop either via MAC address or certificate of something like that, and then if the user connects via any other machine, they would get the RDP portal only.  Not sure there is any way users assigned to multiple portals?

0 REPLIES 0
Labels
Top Kudoed Authors