Chapter 3 Authentication for FortiOS 5.0 : Users and user groups : User groups : Firewall user groups
  
Firewall user groups
Firewall user groups are used locally as part of authentication and can contain any type of user identity except an FSSO group. When a user attempts to access resources controlled by an Identity-Based Policy (IBP), the FortiGate unit requires authentication from that user. If the user authenticates successfully and is a member of one of the permitted groups, the session is allowed to proceed.
This section includes:
SSL VPN access
IPsec VPN access
Configuring a firewall user group
User group timeouts
Viewing, editing and deleting user groups