Skip to main content
Fabio74
New Member
November 11, 2020
Question

Autenticazione in Rete Privata / Authentication on the Private Network

  • November 11, 2020
  • 4 replies
  • 3956 views
Buongiorno Sono un neofita di Fortigate.. Parto subito con una domanda: E' possibile creare una regola che richieda non solo l' autenticazione verso Internet ma anche un'autenticazione verso la Lan Privata ? Al momento sono riuscito a creare questa situazione: In sede viene un' ospite, quando collega il cavo di rete subentra il DHCP che li restituisce un IP della mia LAN. ( il fortigate 60E è regolata per fare da Server DHCP ). Si apre una pagina Web di autenticazione sempre fortigate. Se l'ospite si autentica può navigare, altrimenti no. Il problema è che raggiunge le cartelle condivise ( Anche se bloccate dal Server ) . Vorrei che ci fosse da parte del Fortigate anche in questo caso una richiesta di autenticazione.. è possibile ? grazie e buona giornata Auto translate : Good morning I am a newcomer to Fortigate .. I start immediately with a question: Is it possible to create a rule that requires not only authentication to the Internet but also authentication to the Private Lan? At the moment I managed to create this situation: A guest comes to the office, when the network cable is connected, DHCP takes over and returns an IP from my LAN. (the fortigate 60E is set to act as a DHCP Server). An always strongigate authentication web page opens. If the guest authenticates he can browse, otherwise he cannot. The problem is that it reaches shared folders (Even if blocked by the Server). I wish there was an authentication request from Fortigate in this case too .. is it possible? Thank you and good day

    4 replies

    sw2090
    SuperUser
    SuperUser
    November 11, 2020

    if you have an AD you could use some ad objects and forbid access to servers or services if not a vaild ad user is logged on the client that tries to access.

    lobstercreed
    New Member
    November 12, 2020

    I think the simplest answer is that you need to create a different LAN (subnet/VLAN) for the user and control that access through firewall policy as well.  So instead of just LAN and WAN on the firewall you would have LAN, WAN, and guest network where the user plugs in and gets an IP, then has to meet firewall policies (including authentication) to access either of the other networks.

    Fabio74
    Fabio74Author
    New Member
    November 16, 2020

    Ciao e grazie per la risposta. 

    Non avevo pensato a questa soluzione.

    Ti farò sapere al più presto.

    Grazie infinite per il tuo suggerimento

     

    Hello and thanks for the reply. I hadn't thought of this solution. I'll let you know as soon as possible. Thanks so much for your suggestion

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.