Skip to main content
fred339
Explorer III
October 15, 2022
Question

Populating Fortigate User Groups from Domain User Groups, LDAP and/or FSSO.

  • October 15, 2022
  • 1 reply
  • 3890 views

Fortigate 80F 6.4.10

I have LDAP working on the domain DCs and, I believe, I have FSSO also working (but now I'm not sure why).

The objective is to set up domain user groups as usual - and use those as user groups in the Fortigate.

Then any changes in users and organization would flow from the domain settings into the Fortigate.

That's the idea.

 

There's been good progress with this and it appears that I've actually been focused on LDAP.

If I look at User Definition, I see Type=LDAP, Status=Enabled and Groups is empty!

In User Groups, I have a Group Name list that consists of both "Firewall" and "Fortinet FSSO" entries.

The Firewall entries show Members as the DC names.

The FSSO entries show Members as CN=[domain user group name],OU=xxx,OU=yyy, DC=localname,DC=domain,DC=com.

I don't know why I should care which format is used as long as we can meet our objective.

I only mention this because it may affect which of these group types might be selected or used getting to Users on the Fortigate.

 

So now, I would think that the User definition would include all the Group memberships under "Groups" .. but it doesn't.  
I believe that, at one point, I added a Domain User Group of All Users and the Fortigate User Definition table showed this for each user under Groups.  That seemed right.  

 

I can see that one can manually add a User to a Group on the Fortigate.  But that defeats the purpose of using domain user groups.

What am I missing?  

 

 

 

1 reply

kiri
Staff & Editor
Staff & Editor
October 16, 2022

Hi Fred,

It's a bit unclear to me what are you after.
Can you give me some screenshots?

fred339
fred339Author
Explorer III
October 16, 2022

User w-o User Groups.png

So, here in Edit User, I have selected User Group and clicked on "+".

This causes the Select Entries to appear and it is empty.

As I said:

 I would think that the User definition would include all the Group memberships under "Groups" .. but it doesn't.  

kiri
Staff & Editor
Staff & Editor
October 17, 2022

Hi Fred,

If I understand correctly, you'd like to see in "Select entries" the LDAP groups the user is a member of.
It is not designed like that.
In "Select entries" you can add the groups defined on the Fortigate, left-hand side of my screenshot.

The actual LDAP groups can be defined/configured separately, right-hand side of my screenshot.
Then you can link them together, as I did.
Let me know if this answers your question.

ldap.jpg