Skip to content

FortiGate SSL VPN (CWC-VPN)

Source: _imported/Unifi/CWC-VPN.txt · Applies to: CWC / clubs using FortiGate SSL VPN with Entra SSO · Last reviewed: 2026-07

Purpose

Allow authorized users to connect to the club network via FortiGate SSL VPN using Entra (Azure AD) single sign-on.

Prerequisites

  • User must be a member of the Entra group SG - FortiGate SSO SSLVPN.

Steps

  1. Request access — the user must be added to the SG - FortiGate SSO SSLVPN group in Entra ID.
  2. Once group membership is confirmed, connect to the FortiGate SSL VPN portal at the club's designated URL (e.g., <club-vpn-url>).
  3. Sign in using Microsoft Entra SSO credentials.
  4. Download and launch the FortiClient VPN profile if not already installed.
  5. Connect using the SSL VPN tunnel.

  6. [ ] User added to SG - FortiGate SSO SSLVPN Entra group

  7. [ ] Group membership propagated
  8. [ ] VPN connection tested

Notes / Gotchas

  • ⚠️ This document was imported from minimal source notes and may need expanding with detailed connection instructions, portal URL, and troubleshooting steps.
  • Access is gated solely by Entra group membership; no on-device MFA step is documented in the original source — verify whether the club's Entra Conditional Access policy enforces MFA at sign-in.