Skip to main content
RetchedOne
New Member
December 27, 2012
Question

Poll Active Directory Server

  • December 27, 2012
  • 10 replies
  • 55209 views
Is anyone using " Poll Active Directory Server" with any luck? I' m trying to NOT use the FSSO agent... It is my understanding that i DO NOT need the FSSO agent installed on the DC if I choose the " Poll Active Directory Server" (new 5.0 setting) So far I' m getting no where... And neither is tech support... I set up a LDAP connection (works) Setup a " Single Sign-On" connection and chose " Pol Active Directory Server" I can select the AD group, make rules, and get nothing... no access... not denied, just no access... Log inst much help, neither is debug.

    10 replies

    stephen_ren_FTNT
    Staff
    Staff
    December 30, 2012
    I just tried FSSO polling mode on V5.0.1,it works fine.Have you created the user group and select the group members?And you should create the identity based policy and select the user group in the policy.Pls check your config,especially the policy config.Thanks.
    ZeroInterrupt
    New Member
    January 7, 2013
    Nope.. does not work for me. Fortinet tech support is having a hell of a time with it as well. I can get the groups in and all the and all of the necessary config, but all users show up as guest. The LDAP tests ok from the ' edit LDAP server' , but when i test the authentication via the command line ' diagnose test authserver ldap <LDAP server_name> <username> <password>' and it fails...
    ZeroInterrupt
    New Member
    January 7, 2013
    Update: Just fixed the command line fail issue, but all users still show up as guest. I am going to bounce the firewall tonight to see if that fixes anything.
    rwpatterson
    New Member
    January 7, 2013
    For the work stations, do you use DHCP or are the addresses hard coded?
    msaraiva
    New Member
    February 19, 2013
    It seems that the internal collector does not support NTLM authentication (for instance, computers not joined to domain and non-windows workstations). If you take a look at: # config system fsso-polling # get status : enable listening-port : 8000 authentication : disable There' s no option to enable NTLM authentication like there' s in the Windows based collector. I' ve done a packet trace and the Fortigate does not send a NTLM_CHALLENGE response to the client, it justs reset the connection. Take a look at the traces i' ve attached. fgt_ntlm_broken - Using internal Fortigate Collector fgt_ntlm_ok - Using Windows based Fortigate Collector When using the Windows collector, Fortigate sends a NTLM_CHALLENGE to the user' s browser. This does not happen when the internal Collector is used.
    msaraiva
    New Member
    February 19, 2013
    attach fgt_ntlm_ok.jpg
    msaraiva
    New Member
    February 19, 2013
    attach fgt_ntlm_broken.jpg
    fropert_FTNT
    Staff
    Staff
    February 20, 2013
    @msaraiva NTLM support is actually a new feature request. This has been requested to be implemented in a future release.
    msaraiva
    New Member
    February 20, 2013
    @fropert That' s what i thought when i didn' t see the corresponding setting. Oh well, they shouldn' t have advertised agent-less/collector-less ad based authentication as a big 5.0 feature...
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.