Skip to main content
Belgarioz
Visitor III
May 13, 2019
Question

Force USer Login when Passive Authentication is on

  • May 13, 2019
  • 5 replies
  • 5680 views

Hello,

 

I have a weird question my customer asked me:

 

They have a working passive authentication via Active Directory.

They asked if it is possibile for the administrator to go to a whatever computer and force his credentials to have full access without logging out and logging in with his AD credentials.

To make myself clear, he wants to force his authentication calling some kind of captive portal or telnbet/ssh login to grant him full access.

For some reason a situation similar to the URL filter override but applied to a whole policy.

5 replies

xsilver_FTNT
Staff
Staff
May 13, 2019

Hello,

just switching user and re-using FSSO mechanisms to update logon info for workstation, now with Admin user and respective full-access user group, isn't enough ?

Belgarioz
BelgariozAuthor
Visitor III
May 13, 2019

It's a solution the customer don't want sadly.

 

He came from an old Check Point FW and he was able to telnet the firewall ip to create an active authentication to the firewall

 

xsilver_FTNT
Staff
Staff
May 13, 2019

:D well then, there are no insecure telnet or punch-card slots to read data from, in 21st century firewalls.

 

Maybe you can use REST-API to handle that authentication, hmm ?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!