Skip to main content
harmesh88
New Member
July 30, 2020
Question

Fortiauthenticator interface with Exchange 2019 and Vmware horizone

  • July 30, 2020
  • 1 reply
  • 2610 views
i would like to interface it with Exchange 2019 and Vmware Horizon with many different AD servers.

also we need mobile push auth feature with Fortiauthenticator

Can anyone know process to configure it , i will be very helpful if any one help on this

Regards,
Harmesh Yadav

    1 reply

    xsilver_FTNT
    Staff
    Staff
    September 21, 2020

    Hi,

    FortiAuthenticator do have a help links built in, plus there is Docs site https://docs.fortinet.com/product/fortiauthenticator/6.2 with Admin Guide and Cookbook

    https://docs.fortinet.com/document/fortiauthenticator/6.2.0/administration-guide/454928/fortinet-single-sign-on

     

     

    As you hinted about AD, then maybe you are thinking about FSSO, but then PUSH is more for active authentication, so probably sync users via Remote User Sync Rules to FortiAuthenticator, then group them, let the sync rules assign them FortiToken Mobile units, automatically. So users will be ready for being used.

    Then build RADIUS Service with clients (those who can ask and will be provided with answer as FortiAuthenticator is not reacting to NAS/Clients not configured in advance, no anonymous requestors).

    Ser Policies how those clients will use LDAP realm, LDAP you synced users from, and how it will filter groups and allow users from synced group being allowed to authentication.

     

    Then use this FAC as RADIUS server on FortiGates, or FortiAP/FortiWLC, or even 3rd party devices, to authenticate those users with LDAP as backend and tokens fused in on FortiAuthenticator.

     

    KB - Knowledge Base is another source .. and for PUSH there is this KB (like it? rate it!) https://kb.fortinet.com/kb/search.do?cmd=displayKC&docType=kc&externalId=FD45559

     

    Another alternative is to call Fortinet CSS and negotiate Professional Services, which is paid service where Fortinet's employee will configure the things for you.