Question regarding FSSO operation
Hi all,
We just configured two Firewall rules:
Top Rule: only AD users allow to access the internet and logged.
Bottom Rule: Any is denied and logged.
I just got some issues when using FSSO with Firewall policy AD-based authentication.
1. Let say user A login to PC A (192.168.1.2/24), then he moves to the next PC B (192.168.1.3)and logs in.
When the user moves back to PC A, he finds that he has no internet access now.
Issue: Is there any way to allow Fortigate to "Know" more than one Lan IP as its record so this problem can be avoided?
2. I wonder what if I set up the Lan interface to enable "Security mode" with Captive Portal.
Let's say above user A now still has no internet access, but redirect to the captive portal.
Once he is authenticated, he will be hit by my top rule now.
Issue: What is going on with PC B now? Will it lose internet connection then? - So new authentication is now needed for PC B.
