Fortinet Provides Technical Guidance for Immediate Removal of Dial-Up VPN Users from FortiGate Access
Fortinet has issued a technical tip detailing how to immediately remove a dial-up VPN user from VPN access on a FortiGate device without affecting other connected users. This guidance is crucial for network administrators who need to revoke access swiftly, for instance, in cases of security breaches or policy violations. The solution involves either disabling or deleting the specific dial-up user account, or removing the user account from the VPN access group defined in the phase1 settings. Additionally, administrators can delete phase1 for specific users by utilizing their public IP addresses in the phase1 filter. The article provides specific command-line interface (CLI) commands for FortiGate devices, including `diagnose vpn ike filter dst-addr4 diagnose vpn ike gateway flush` or `diagnose vpn ike filter dst-addr4 diagnose vpn ike gateway clear`. For FortiOS version 7.4.1 and later, updated commands such as `diagnose vpn ike gateway filter rem-addr4 diagnose vpn ike gateway flush` or `diagnose vpn ik...