Nested Groups in AD
Hi, we have configured in our company the integration between Active Directory (LDAP) and our Fortigate 60C (FortiOS 5.2.3) and we want to enable the nested detection for LDAP in FortiOS. The goal of this is to use a AD group which gives access to the VPN where we can put other groups inside which user receive that access too.
Actually we put other groups under the first one, and that users cannot access to the VPN, receiving a permission failure. If we put those users in the parent group, they receive the correct permission and they can use the VPN. Therefore, enabling the nested configuration with command "set search-type nested" would fix this issue? We are not using at this moment the SSO.
I have another question... if we want to rollback this change, how can we change it to the default behaviour? I have not found any information in the handbook.
Thank you very much
