12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User groups<br />

User<br />

Override Time<br />

Protection Profiles<br />

Available<br />

Permission Granted<br />

For<br />

Configuring SSL VPN user group options<br />

Go to User > Group and select the Edit icon for an SSL VPN user group. Expand<br />

the SSL-VPN User Group Options section.<br />

For detailed instructions about how to configure web-only mode or tunnel mode<br />

operation, see the <strong>FortiGate</strong> SSL VPN User <strong>Guide</strong>.<br />

Figure 266:SSL-VPN user group options<br />

Select to set the duration of the override:<br />

Constant Select to set the duration of override in days,<br />

hours, minutes.<br />

Ask<br />

Select to allow the authenticating user to<br />

determine the duration of override. The duration<br />

set is the maximum.<br />

List of defined protection profiles configured (available for Firewall<br />

or Active Directory user groups only).<br />

One protection profile can have several user groups with override<br />

permissions. Verification of the user group occurs once the<br />

username and password are entered. The overrides can still be<br />

enabled/disabled on a profile-wide basis regardless of the user<br />

groups that have permissions to override the profile.<br />

Select the protection profiles that will have override privileges within<br />

the user group.<br />

Enable SSL-VPN Tunnel<br />

Service<br />

Allow Split Tunneling<br />

Restrict tunnel IP<br />

range for this group<br />

Select to allow users in this group to connect to the network<br />

behind the <strong>FortiGate</strong> unit using the SSL VPN tunnel. Not<br />

available in Transparent mode.<br />

Select to allow split tunneling for this group. Split tunneling<br />

ensures that only the traffic for the private network is sent to<br />

the SSL VPN gateway. Internet traffic is sent through the<br />

usual unencrypted route.<br />

Type the starting and ending IP address range for this group<br />

if you want to override the Tunnel IP range defined in VPN ><br />

SSL > Config.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

392 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!