Fortiweb and RDS Gateway
Hi,
I'm working on a solution with the Fortiweb and a RDS Gateway and 2FA (fortiauthenticator).
I've got the 2FA part working with the RDS Gateway. Users get a login page and after they are authenticated they are redirected to the RDWEB page. All is fine.
Now i got a security issue where users are able to bypass the 2FA.
When you access the RDWEB page and click on a RDP session a RDP link is downloaded to the client. In normal situation this is opened immediately. Now when i log out and click on the RDP link can authenticate directly to the RDS Gateway, and are bypassing the Fortiweb Authentication page and the 2FA. This is always posible, even several days after the last login.
I Configured a session cookie timeout, but this does not seem to fix this issue. I think i am missing something like a session timeout or something.
FortiWeb-VM 5.50,build0697
Any help is appreciated!
Regards, Alex
