Skip to main content
AlexW
Visitor III
March 7, 2016
Question

Fortiweb and RDS Gateway

  • March 7, 2016
  • 6 replies
  • 13775 views

Hi,

 

I'm working on a solution with the Fortiweb and a RDS Gateway and 2FA (fortiauthenticator).

I've got the 2FA part working with the RDS Gateway. Users get a login page and after they are authenticated they are redirected to the RDWEB page. All is fine.

 

Now i got a security issue where users are able to bypass the 2FA.

When you access the RDWEB page and click on a RDP session a RDP link is downloaded to the client. In normal situation this is opened immediately. Now when i log out and click on the RDP link can authenticate directly to the RDS Gateway, and are bypassing the Fortiweb Authentication page and the 2FA. This is always posible, even several days after the last login.

 

I Configured a session cookie timeout, but this does not seem to fix this issue. I think i am missing something like a session timeout or something.

 

FortiWeb-VM 5.50,build0697

 

Any help is appreciated!

 

Regards, Alex

    6 replies

    dooasmi
    New Member
    March 21, 2016

    Are you using security groups for 2FA?

    AlexW
    AlexWAuthor
    Visitor III
    March 30, 2016

    With security groups, are you refering to the fortiauthenticator ?

     

    The direct opening of the RDP file does not get authenticated against the Fortiauthenticator, but this goes straight to the RDS Gateway, there it is authenticated against AD. (so no 2fa)

     

    The Fortiweb is stil in the middle of the connection but does not stop this direct connection..

    AlexW
    AlexWAuthor
    Visitor III
    August 8, 2016

    I figured it out, When the RDP link is opened it goes to another folder witch does not have authentication on it so that's why it is passing it. If i put authentication on that folder "RDP over https" is not working anymore.

     

    This is because Authentication is not passed from the browser to the RDP application (mstsc) You should see it like you click on a link in chrome and a firefox page is opened. an all new application so an all new authentication process. So an authentication cookie does not work in this situation.

     

    Does anyone know if you can authenticate a session regardless of which application makes the initial connection ? so when you open a second browser (this case RDP/mstsc) you do not have to authenticate again ?

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!