FSSO Groups on the SSL Interface (6.0.x Only)
-
Enable “Multiple Interface Policies” features under System->Feature Visibility
This allows an interface option called “all”
-
Create a new IP Address Range, using the SSLVPN range
Note: There is a range there by default but its tied to the SSLVPN Interface and can’t be used with interface “all”
-
Create a new firewall Policy using:
-
Incoming Interface “any”
-
Outgoing interface to FortiNAC Eth1
-
Source is new SSLVPN IP Range and FortiNAC FSSO Group for Rogues
-
Destination could be refined to just FortiNAC Eth1 interface
-
Service could be refined to DNS, HTTPS, DHCP, Agent (4567/4568)
-