FSSO DC Agent Mode, how to handle user logins from "non-domain-joined" devices?
Hi,
For one of our customers we would like to implement FSSO in Agent Mode (FOS 5.4.x).
We will use FSSO only to control direct Internet access and therefore map the Webfilter-Profiles based on FSSO-User-Group in the firewall policy.
The question now is, how can we handle users logging in to the network on "non-domain-joined" clients (e.g. BYOD's like MacBook)?
I was just thinking about just using additional firewall policies with simple LDAP-Groups added to the source, so Users with "non-domain-joned" clients get presented a login form in their browsers when accessing the network for the first time. Unfortunately users then need to re-authenticate manually at least all 24h and this is definitely not what the customer want...
Of course the best solution would be to domain-join the BYOD devices like MacBooks but this is a more political then technical discussion I don't want to start yet...
Any ideas? How about your FSSO projects?
Thanks a lot for feedback
Regards
Thrillseeker