Authentication for Inbound Policy
I am replacing Juniper SSG Firewalls at a clients site with Fortigate 60E Units. Everything setup fine except one inbound policy the Junipers managed before. We have an RDP server at the site and remote users would need to authenticate against the Juniper Firewall before RDP was available (so the RDP is not open the world for hacking). The method used was we had a simple website running on an internal webserver that the remote user would browse to (via DNS name pointing to Virtual IP) and an authentication windows would pop up (from the Firewall), once a local firewall user credentials were entered the website would then load up (the site was simply a page we created to say firewall authentication was successful) then any another policy that also had 'Auth' enabled was available to the user that had successfully authenticated so the user could RDP direct to the RDP server.
I see forums and posts about creating policies to allow internal people access to outside resources but this is a need for Firewall authentication for remote people accessing internal (RDP) resource, as I say this means RDP is not open until you authenticate against the firewall. I've created the local Firewall user and created a Group and added the local Firewall user to the group, I just don't see how to only have the policy active once the user is authentication.
Any help, much appreciated.
Thanks,
Matt.
