Skip to main content
dbg_algis
New Member
September 30, 2019
Question

Fortigate and RDS server - block specific AD users only

  • September 30, 2019
  • 1 reply
  • 2404 views

Hello, We, currently, have few RDS servers. We want to block traffic to WAN only for specific users (not all) in specific RDS server. Naturally to do that we have to identify users somehow. I watched few CookBooks on Youtube (f. e. [link]https://www.youtube.com/watch?v=Il8u-3wJjfc).[/link] It's pretty simple (Authentificate users via Captive portal). However maybe someone knows how Fortigate works with RDS servers (one device and multiple users)? Will, Fortigate block only "required users" or it will "block all users" on user identified machine?

Another aproach is to simply migrate all "required to block users" to one server and remove "all not required to block users" from that server. However we try to avoid this approach.

Also if someone has ideas (another aproaches) – I'm listening.

Thanks.

    1 reply

    Alivo__FTNT
    Staff
    Staff
    October 1, 2019

    Hello,

    one approach can be to place users you want to have access (or not) in specific AD group and

    then allow or disallow such group in firewall policy. You can also chose not to monitor the specific

    group for logon events. This way they won't have an auth session in FortiGate and won't match fw policy (unless there is some that would allow them without auth).

     

    Best Regards,

    Alivo