Associating user logins through RADIUS/RSSO with logins through LDAP/FSSO...
...or enforcing per user web filter quotas across login mechanisms.
Good Day.
I'm nearing completion of the initial configuration of our new Fortinet firewall (FG-200D, FortiOS 5.2.3). It's my first experience with the product/company and, in all, I'm impressed and pleased with the purchase. One of a few areas I'm struggling to get the behavior I seek is relative to web filtering.
We're using FortiCollector/agent based FSSO for our Windows AD workstations and also support BYOD over wireless utilizing 802.1X with RADIUS authentication. I've configured a policy that allows for 60 minutes of browsing sites in the General Interest - Personal category throughout the workday (with a generous lunch period definition that does not include the timer). The policy seems to work well, with one exception noticed so far. When a user consumes their quota on their workstation, a separate quota counter for their same account authenticated through RADIUS to connect to the WLAN still provides a means to circumvent the policy.
Last night I configured RSSO (thanks to the document at http://docs.fortinet.com/d/fortigate-rsso-with-windows-server-2008-nps/download), thinking it may hold the key to associate the user account authenticated through LDAP/FSSO with the same user account authenticated through RADIUS/RSSO. Alas, in spite of my success early this morning tracking the RSSO logins through User & Device > Monitor > Firewall, I could see in Log & Report > Security Log > Web Filter that separate timers incremented for my (work related, honest) personal browsing activity on my workstation and on my smartphone.
Is it possible to achieve this unified quota approach and can any guidance be offered?
Thanks,
Stan