Skip to main content
Mes-Lili2
Explorer III
September 22, 2023
Question

AD Integration

  • September 22, 2023
  • 21 replies
  • 8686 views

I am looking to add AD users and groups to firewall policies.

Do i need to use FSSO collector agent or can i just set a remote group in "user groups" via LDAP.

Many thanks

21 replies

gsekar
Staff
Staff
September 22, 2023

Hi

You can configure remote user group via the LDAP please refer the below document for configuration .

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-FortiGate-to-use-an-LDAP-server/ta-p/196141

 

 

Mes-Lili2
Mes-Lili2Author
Explorer III
September 22, 2023

Thanks for the reply, this shows me how to add user groups into policies but my firewall is only seeing me as an ip address so i need to enable user identification and this is what i need advice on. thanks again..

mle2802
Staff
Staff
September 22, 2023

Hi @Mes-Lili2

As said in the document "Users that have been imported from the LDAP server, can be used to enforce user based policies as permission sets and allow VPN connections", this is use case for VPN policy. In order to have policy based on user, you may want to take a look at FSSO or active directory polling. Please refer to this document for more information "https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/888827/poll-active-directory-server"

Regards,
Minh

ebilcari
Staff
Staff
September 22, 2023

If you want to do what is called passive authentication, apply policies based on AD user groups without asking the user to authenticate you have to use FSSO. This is explained in the documentation guide. You can configure FGT to poll directly the AD for events or install a collector agent on the AD (better scalability):

polling.PNG

Basically FSSO will tie the user with its IP based on their domain logins events, than the user is tied to a FSSO group that is applied to a policy.

fsso-user.PNGLDAP groups are used for active authentication, users will be prompted to enter their credentials again.

Emirjon
Mes-Lili2
Mes-Lili2Author
Explorer III
September 22, 2023

Yes I am now polling the AD server directly but my authentication seems to be failing. I am using UPN as suggested in documentation and testing directly on an AD sever i can authenticate but via tha active directory connector within external connectors it fails. thanks all for your help here..

ebilcari
Staff
Staff
September 22, 2023

Is the LDAP server configured correctly? Can you share the output of this command:

diagnose debug fsso-polling detail 1

The local firewall on the server should allow the connection and the user credentials should have privileges to read the events.

I would still suggest to download and use FSSO collector, is free to use and you can get it from the support page

fsso collector.PNG

Emirjon
Kush_Patel
Staff
Staff
September 23, 2023
Mes-Lili2
Mes-Lili2Author
Explorer III
September 26, 2023

It seems the Fortigate is trying to connect on SMBV1, this is not enabled on our DC's so need to force V2. I can only see docs on ssl vpn SMB so as i trawl away perhaps someone could point me in the right direction...

 

ebilcari
Staff
Staff
September 26, 2023

By default it should be disabled, you can verify it here :

GW (fsso-polling) # show full
config user fsso-polling

set smbv1 disable
set smb-ntlmv1-auth disable 

This debug may help:

diag debug application fssod -1
diag debug enable

 

P.S Collector agent is still the recommended way of doing this :)

Emirjon
TuncayBAS
Explorer
September 26, 2023

It is best to use FSSO. Just using ldap as a local collector in Fortigate cannot fully manage AD traffic.

But if it uses FSSO, you can easily capture users' group changes and when there is more than one DC, it will be easier for you to manage them via FSSO.

Mes-Lili2
Mes-Lili2Author
Explorer III
September 26, 2023

OK once again many thanks all for the info..

so... I have gone FSSO with collector and the collector to AD is working fine as can see all logged in users in collector logs.

 

I have set FSSO client to use collector and added lDAP server for groups.

 

when I go into a policy I can add the group seen by the FSSO but although I am a member of that group my policy fails.  in log forwarding when group is not applied I can see my traffic allowed and my username in the source field...    however ... I have noticed that it does not include the domainname\username  like it does on the collector so perhaps this is my problem.

 

If the domain name does not show in user source, how am i supposed to differentiate between different domains,,

 

Many thanks in advance.... and yes I have downloaded many docs but to no avail.

Mes-Lili2
Mes-Lili2Author
Explorer III
September 27, 2023

OK got AD groups working by just letting FSSO agent populate/collect group info...  I am now looking to see the command to show group membership

For palo alto .. show user group name <usergroupname>

 

I am also looking to see how to add individual AD users into policies...

any help much appreciated.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.