Skip to main content
nbcuser
New Member
September 6, 2015
Solved

Optional authentication for extra web access

  • September 6, 2015
  • 2 replies
  • 6954 views

Hi All,

 

I am a P-12 school and have a 300C running 5.2.3.  We have a mix of PCs, Macs and iPads.  While we have a Windows AD Domain not all of our devices are bound or login to the domain.  We don't have access to our WLC to do any Radius authentication.

 

I'd like to setup the ability for staff to optionally authenticate with the Fortigate to gain extra web access.  This would allow them to access sites that are deemed inappropriate for the students.  I don't want to force the staff to have to authenticate all the time, and I don't want all our students to have to authenticate either.

 

I am quite new to the Fortigate so am wondering how others would go about achieving this?

 

Thanks in advance,

Chris.

    Best answer by emnoc

    I had that same issue but here's what we did. In our approach we worked with a pubicschool who had the same issues

     

       > a mix of PCs/MACs/

       > FSSO was out of the question

       > principal, police, resource officers,etc... got tired of being denied to just about anything nasty

       > etc.....

     

    So we crafted a sslvpn group for faculty/staff/contractors/etc...

    Allow them SSLVPN from  the local-lan or wifi,  with a security that was non or less restrictive than the students. The staff only needed to install a forticlient,  and life was full of gold at the end of the rainbow so to speak.

     

    FWIW: The SSLVPN groups had full-to-unrestricted access from WEB ssh /telnet , etc....based on that group need,  and you SNAT the sslvpn ipv4-pool with the correct policies.

     

     

     

    2 replies

    emnoc
    emnocAnswer
    New Member
    September 6, 2015

    I had that same issue but here's what we did. In our approach we worked with a pubicschool who had the same issues

     

       > a mix of PCs/MACs/

       > FSSO was out of the question

       > principal, police, resource officers,etc... got tired of being denied to just about anything nasty

       > etc.....

     

    So we crafted a sslvpn group for faculty/staff/contractors/etc...

    Allow them SSLVPN from  the local-lan or wifi,  with a security that was non or less restrictive than the students. The staff only needed to install a forticlient,  and life was full of gold at the end of the rainbow so to speak.

     

    FWIW: The SSLVPN groups had full-to-unrestricted access from WEB ssh /telnet , etc....based on that group need,  and you SNAT the sslvpn ipv4-pool with the correct policies.

     

     

     

    nbcuser
    nbcuserAuthor
    New Member
    September 6, 2015

    Thanks emnoc,

     

    that's an interesting suggestion - one that I hadn't considered - and I shall definitely investigate it further.

    Cheers,

    Chris.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.