cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2175
Views
10
Helpful
3
Replies

Remote VPN Forti client with AnyConnect Posture

amirminhat
Level 1
Level 1

Hi,

 

I do have a setup where the environment is using Forti Client VPN for their remote access VPN. In this scenario, I want to enforce a posturing and client provisioning with AnyConnect but using Forti Client as the remote VPN.

 

I tried to find any documentation of ISE posturing with the third party products but to no avail. Has anybody done this ? Appreciate if can help on how to deploy the posturing for this scenario.

 

Thanks

1 Accepted Solution

Accepted Solutions

Yes but this doesn't work last time I tested.  FortiGate didn't support CoA for VPN users, only those on managed switches or APs.  FortiGate also doesn't support URL redirection for SSL VPN clients.  Finally, the ISE DHCP/DNS server cannot be used here since FortiGate does not support DHCP relay for VPN clients.

View solution in original post

3 Replies 3

HI @Lauren957 

 

I just want to understand this, do you mean we can run both VPN client Fortinet and Cisco Anyconnect at the same time ? How does anyconnect provide secure vpn access to the Forticlient VPN ? If so, how does ISE trigger to for client provisioning for posturing if we are using Forticlient ?

crediblebh
Level 1
Level 1

Just so I'm clear, you're saying that Fortinet and Cisco's AnyConnect VPN clients can coexist? When connecting to the Forticlient VPN, how does anyconnect ensure a secure connection? If that's the case, how does ISE communicate with Forticlient to initiate client provisioning for posturing? CredibleBH

Yes but this doesn't work last time I tested.  FortiGate didn't support CoA for VPN users, only those on managed switches or APs.  FortiGate also doesn't support URL redirection for SSL VPN clients.  Finally, the ISE DHCP/DNS server cannot be used here since FortiGate does not support DHCP relay for VPN clients.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: