Skip to main content
lexdef
New Member
April 1, 2025
Question

How to force FClient to only validate connections only via SSO

  • April 1, 2025
  • 2 replies
  • 786 views

Hi all,

Users connecting via VPN must be validated via SSO (the IdP is Azure). The problem arises if the user chooses to authenticate via LDAP; the queries reach the server, allowing an attacker to cause a DoS.

Force this option in fclient is not an option cause anyone from outside our organization could do it.

Has anyone encountered this problem?

Thnks in advance!

 

 

2 replies

yderek
Staff
Staff
April 1, 2025

HI, @lexdef

 

Is your intention to block the Dos/DDOS attack targeting on your LDAP server using SSLVPN ?

 

When you say the user trying to use LDAP credentials, do they successfully logged in? Or you just seeing the attempt that some random user trying to access your SSLVPN using LDAP credential against your LDAP server 

lexdef
lexdefAuthor
New Member
April 2, 2025

Hi yderek,

What I need is to force fclients to log in with SSO, and disable this authentication via LDAP.

If the user decides to authenticate via LDAP the query could arrive at the server, and an attacker could cause a DoS attack.

Thanks!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!