EasyManuals Logo

Fortinet FortiGate Series Administration Guide

Fortinet FortiGate Series
764 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #674 background imageLoading...
Page #674 background image
User Group User
FortiGate Version 4.0 MR1 Administration Guide
674 01-410-89802-20090903
http://docs.fortinet.com/ • Feedback
Figure 420: Using RADIUS records to assign IP addresses for SSL VPN Tunnel Mode
5 Go to User > User Group and create a new user group or edit an SSL VPN user group.
6 Set Type to SSL VPN.
7 Select the name of the Portal that contains the tunnel mode widget.
8 Add the RADIUS server that assigns IP addresses to the Members list and save the
SSL VPN user group.
9 Go to Firewall > Policy and select Create New.
10 Set Action to SSL VPN.
11 Add an identity based policy and add the SSL VPN user group containing the RADIUS
server and the portal to the Selected User Groups list.
12 Configure the remaining firewall policy settings as required.
To dynamically assign IP addresses for dialup IPSec VPN
To use a RADIUS server to assign IP addresses for dialup IPSec VPN users you
configure an IPSec DHCP server for your IPSec VPN configuration and configure
advanced settings to set IP Assignment Mode to User-group defined method. You must
also add the RADIUS server to a firewall user group. Then in the phase 1 configuration of
the dialup VPN you configure advanced settings to set XAUTH to server mode and select
the firewall user group that you added the RADIUS server to.
1 Go to System > DHCP and add or edit the IPSec DHCP server used by the IPSec VPN
configuration.
2 Select Advanced and set IP Assignment Mode to User-group defined method and save
the changes to the DHCP server.
3 Go to User > User Group and create a new user group or edit a Firewall user group.
4 Set Type to Firewall.
5 Add the RADIUS server that assigns IP addresses to the Members list and save the
Firewall user group.
6 Go to VPN > IPSec and create or edit a User Phase 1 with Remote Gateway set to
Dialup User.
7 Select Advanced.
8 Set XAUTH to Enable as Server.
9 Set User Group to the firewall user group containing the RADIUS server.
10 Configure the remaining IPSec VPN settings as required.

Table of Contents

Other manuals for Fortinet FortiGate Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Fortinet FortiGate Series and is the answer not in the manual?

Fortinet FortiGate Series Specifications

General IconGeneral
ModelFortiGate Series
CategoryFirewall
ThroughputVaries by model
InterfacesVaries by model
Concurrent SessionsVaries by model
VPN SupportYes
High AvailabilityYes
Firewall ThroughputVaries by model
VPN ThroughputVaries by model
IPS ThroughputVaries by model
NGFW ThroughputVaries by model
Threat Protection ThroughputVaries by model
New Sessions per SecondVaries by model
Power SupplyVaries by model
Security FeaturesFirewall, IPS, Application Control, Web Filtering, Antivirus, VPN
Virtual DomainsYes
Form FactorDesktop, Rackmount

Related product manuals