Question
FSSO and WebFiltering
Hello, We are trying to configure FSSO and Web Filtering but without much success. The topology of the network is as follows: a. LAN > ISA > FortiGate (Transparent) > WAN b. All users on LAN are routed from the ISA server. ISA server is also the 2nd Domain Controller. c. Primary Domain Controller has the FSSO Collector and Agent. d. We have published the 389 port from DC1 to ISA(DC2) so that FortiGate can use the FSSO. e. We have setup and imported the required Groups on FortiGate (FSSO) and if we execute the following command on CLI we get the required results: CLI > diagnose debug enable CLI > diagnose debug authd fsso server-status Server Name Connection Status Version ----------- ----------------- ------- FSSO DC connected FSSO 4.3.0151 f. If we issue the diagnose debug authd fsso list we get the list of users authenticated (more than 100 entries) e.g. IP: 192.168.1.135 User: xxx IP: 192.168.1.138 User: xxx …………. g. Under the Policy we have setup the authentication with a web profile to block or monitor user activities. h. However on the logs we see only 3-4 users from the domain and all the rest are shown as “Guestâ€. These are allowed since we also include the FSSO Guest groups. i. Problem is that 100+ users go out as Guests, although they are part of the groups from the domain and have authenticated. Please advise how we can also identify all users and configure the require web filtering policy. At the moment although the web filter profile is applied, the reports created with the Guest accounts do not provide any insight. It seems that FortiGate does not recognize most users from the Domain, the connection between the FSSO Collector and Fortigate works. Do we need to forward any other port besides 389 on the ISA? FortiGate is placed transparently in front of the ISA server and before the WAN. The Collector Agent seems to work, but for some reason, FortiGate sees 100+ users as Guests, and only 3-4 as actual users. WAN Modem IP: xxx.xxx.xxx.xxx FortiGate IP: xxx.xxx.xxx.x ISA NIC1 IP: xxx.xxx.xxx.x ISA NIC2 IP: 192.168.1.2 DC1 IP: 192.168.1.1