User Group
User
FortiGate Version 4.0 Administration Guide
584
01-400-89802-20090424
•
SSL VPNs on the FortiGate unit
“Configuring SSL VPN identity-based firewall policies” on page 331
•
IPSec VPN Phase 1 configurations for dialup users
“Creating a new phase 1 configuration” on page 534
.
Only users in the selected user group can authenticate to use the VPN tunnel.
•
XAuth for IPSec VPN Phase 1 configurations
See XAUTH in
“Defining phase 1 advanced settings” on page 536
.
Only user groups in the selected user group can be authenticated using XAuth.
•
FortiGate PPTP configuration
“PPTP configuration using FortiGate web-based manager” on page 547
Only users in the selected user group can use PPTP.
•
FortiGate L2TP configuration
You can configure this only by using the
config vpn l2tp
CLI command. See the
Only users in the selected user group can use L2TP.
•
Administrator login with RADIUS authentication
“Configuring RADIUS authentication for administrators” on page 214
Only administrators with an account on the RADIUS server can log in.
•
FortiGuard Web Filtering override groups
“FortiGuard - Web Filter” on page 487
.
When FortiGuard Web Filtering blocks a web page, authorized users can authenticate
to access the web page or to allow members of another group to access it.
For each resource that requires authentication, you specify which user groups are
permitted access. You need to determine the number and membership of user groups
appropriate to your authentication needs.
Firewall user groups
A firewall user group provides access to a firewall policy that requires authentication and
lists the user group as one of the allowed groups. The FortiGate unit requests the group
member’s user name and password when the user attempts to access the resource that
the policy protects.
You can also authenticate a user by certificate if you have selected this method. For more
information, see
“Adding authentication to firewall policies” on page 327
.
A firewall user group can also provide access to an IPSec VPN for dialup users. In this
case, the IPSec VPN phase 1 configuration uses the Accept peer ID in dialup group peer
option. The user’s VPN client is configured with the user name as peer ID and the
password as pre-shared key. The user can connect successfully to the IPSec VPN only if
the user name is a member of the allowed user group and the password matches the one
stored on the FortiGate unit.
For more information, see
“Creating a new phase 1 configuration” on page 534
Note:
A user group cannot be a dialup group if any member is authenticated using a
RADIUS or LDAP server.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...