Skip to main content
Deltarr
New Member
January 9, 2018
Question

Guest user is seen as domain user

  • January 9, 2018
  • 6 replies
  • 17144 views

Hello,

 

Our webfilter is flow-based and we have several AD groups that each have specific web filtering profile (from no access to full access) Everything is working fine for all users, the sites that need to be blocked are blocked. My problem is when a guest connect to our Wifi. Sometimes (it's definitely not all the time), the web filter will restrict ALL sites. I created a replacement page to get some information and I can see that the guest user (not in the domain) is referred to as a generic user that exist in our AD

 

Since english is not my main language, here is a short example

 

on the domain, user "ABC" is part of the group "No access" This group is linked to a web filter profile on fortigate that allow no websites access

If I log with the user "ABC" and try to connect to any website, I get fortigate blocked page (wich is what I want) Now, a guest comes in our office, connect to our wifi (sadly we don't have separate access) to get internet access. Sometimes, he will be blocked as if he was user ABC (the username on the block page is "ABC") How can I be sure that users that are not part of the domain, that use computer that are not part of the domain, don't get this problem ? I hope I'm clear enough...  Let me know if you need more information Thank you for your help

 

 

    6 replies

    dmcquade
    New Member
    January 10, 2018

    How do you have AD integrated with the Fortigate? If the group object is an FSSO group, make sure you enable FSSO on the rule in the advanced options

    Deltarr
    DeltarrAuthor
    New Member
    January 10, 2018

    I have 4 groups created in AD (All my AD users are member of 1 of these) and each one is member of a FSSO group on the Fortigate

    Each one has a specific web filter rule (flow-based / SSL inspection) assigned to it

     

    What options are you speaking of ?

     

     

    What I don't understand is why a non-domain user using a non-domain computer is recognized as a domain user by the webfilter... note that he is never asked to enter any credentials at any time He is logged with his local username

    and to be clear, it has happened to other people (no relationship between them) as well

     

     

    Thank you !

     

     

     

    dmcquade
    New Member
    January 13, 2018

    This option is available via the CLI or if you are using a FortiManager, the advanced options section. From the CLI run

    config firewall policy

    edit <policyId>

    set fsso enable

    end

     

    If this option is set to disabled (default setting) it will ignore FSSO users and groups. Your guests are not authenticated to your AD. They are simply being allowed on the rule because the groups assigned to the rule are being ignored.

     

    Hope that helps.

    d

    Deltarr
    DeltarrAuthor
    New Member
    January 16, 2018

    We did the following:

     

    AD:

    4 groups populated by user accounts (Full, Basic, Strict and No Access)

     

    Fortigate:

    4 User Groups (Fortinet Single Sign-On) each one having AD group as a member

    4 policies (using the 4 groups) + one without webfilter

     

    Order of policies (LAN - WAN):

    No Access

    Strict

    Basic

    Full

    All (no webfilter)

     

    Detail of BASIC Webfilter policy:

     

     

     

    The guest user gets the block page as if he was connected as one domain user (user account "VideoCad")

    This is a generic user logged on several computers in the company

     

    If I want to test this account, I open Chrome as this user (the account has a password) and I can check that the webfilter is working as intended. I tested to log to CNN.com

     

    [code lang=css]date=2018-01-16 time=09:32:06 logid=0316013056 type=utm subtype=webfilter eventtype=ftgd_blk level=warning vd="root" policyid=12 sessionid=61269217 user="VIDEOCAD" srcip=192.168.120.119 srcport=61020 srcintf="internal1" dstip=151.101.1.67 dstport=80 proto=6

     

    service=HTTP hostname="www.cnn.com" profile="NO ACCESS" action=blocked reqtype=direct url="/favicon.ico" sentbyte=366 rcvdbyte=0 direction=N/A msg="URL belongs to a denied category in policy" method=domain cat=36 catdesc="News and Media" crscore=30 crlevel=high

     

    Thanks again for your help :)

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!