Skip to main content
NothingKai
New Member
October 18, 2016
Question

[Help] FSSO Authenticated with User Domain

  • October 18, 2016
  • 3 replies
  • 5587 views

Hi guys,

 

Sorry if you cannot understand, because my english very bad.

 

I have a issue.

 

I setup FSSO on fortigate 100D with my AD. But when user belong AD login on 1 PC has join domain, fortigate request Authenticated Requies on browser.

 

I need:

 

- Authenticated Requies on browser only show if the device or the user does not belong AD.

- If user belong AD and login on device has join domain, not show Authenticated Requies on browser. That user will access internet with Policy on firewall.

 

Thanks for support. Please help me :(

3 replies

heskez
New Member
October 18, 2016

Hi NothingKai, 

 

Have you tried to follow the steps in the FSSO Cookbook? 

http://cookbook.fortinet.com/tag/fsso/

 

 

NothingKai
New Member
October 19, 2016

heskez wrote:

Hi NothingKai, 

 

Have you tried to follow the steps in the FSSO Cookbook? 

http://cookbook.fortinet.com/tag/fsso/

 

 

Yes, I tried it, but cannot :(

xsilver_FTNT
Staff
Staff
October 26, 2016

Hi NothingKai,

if I got your situation correctly then .. - you have working FSSO, user's logon to workstation is spotted and propagated to FortiGate, and when user browse the protected resources (Internet access probably), then is seen by FSSO user group in policy, policy applied and passive authentication is done and traffic allowed without any active auth request (pop-up for auth on user's browser).

- then you have non-domain users which you'd like to authenticate. But for this I do not have any idea where you can authenticate those. For simplicity you can use local FortiGate users or Guest Management on FortiGate for visitors. For those make a firewall group similar to step 4. in following guide. Then make firewall policy for this group as in step 5. but make sure it's placed bellow your FSSO policy. FortiOS 5.2 and 5.4 has implicit fall through for unauthenticated users, so next user identity policy will be tried. Pay attention to fact that if there is any non-identity (pure IP based) policy handling the same traffic pattern (src/dst/ports) then it will be tried and used first. So if it blocks/allow traffic then there will be no identity check at all.

 

Guide I was referring to is here : http://cookbook.fortinet.com/providing-single-sign-using-ldap-fsso-agent-advanced-mode-expert/

 

Best regards, Tomas

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!