Firewall Group vs Fortinet SSO Group
I have the FSSO Agent installed on both of my Domain Controllers and it's wired up to my FortiGate.
It seems logical to me that I would want to create groups on the FortiGate that come from Active Directory. This way, whenever I add or remove a user from my AD group, it auto syncs with the Firewall.
On the FortiGate I found 2 ways to link an AD Group to the Firewall.
Method 1:
Create a new Group. Select Firewall.
In the Remote Groups section click the Add button.
Select my domain controller.
Select the Active Directory group from the list.
Method 2:
Create a new Group. Select Fortinet Single Sign-On (FSSO)
Select the Active Directory group from the list.
Same end result? What's the difference? Benefits of one over the other?
