Skip to main content
gprentice
New Member
March 12, 2018
Question

SSO on SSL-VPN Portal RDP using a domain (Fortigate 60E f/w ver=5.6.3)

  • March 12, 2018
  • 8 replies
  • 15516 views

When logging in manually to the RDP client, the domain is automatically selected, and the user logs in OK. (user does not have to specify the domain name)

 

However, when selecting SSO in the portal settings, clicking RDP fails login showing the local name of the server with the username.   We would like to use domain credentials, not local computer name credentials.

Tried making the domain default on the Windows Server 2012R2 server, but this problem still exists.

Any ideas?

    8 replies

    Elthon_Abreu
    New Member
    March 14, 2018

    Hi gprentice,

     

    If I got it well... You have a SSL VPN with LDAP/AD login. Right?

     

    So, you want to log in to SSL VPN Portal and access an RDP environment with the same LDAP user. I have a similar demand and I use my login username like "username@domain.net" + password, or I configure a bookmark in Portal template.

     

    I hope it helps.

     

    Cheers,

    Elthon Abreu

    gprentice
    gprenticeAuthor
    New Member
    March 14, 2018

    Thanks, that might be a good workaround, but I was hoping it would be simpler for the users (who sometimes have trouble remembering their username, let alone a domain name too)

     

    Graham

    Elthon_Abreu
    New Member
    March 15, 2018

    Graham,

     

    Try the second option... configure your Portal template with SSO... that will "use" the same login of VPN logon. It works for me... my users just click on bookmark link and the RDP session opens.

     

    Cheers,

    GabrielSanchez
    New Member
    March 18, 2019

    I have the same issue on a FG200E running 6.0.4. I also tried forcing the default domain using GPO, but did not resolved the issue.

     

    This is what worked for me:

    1. On the server that you are trying to RDP to, make sure you force to use NLA.

     

    2. on the Bookmark, select SSO and let the server pick the security.

     

     

    Hope this helps,

    Gabriel

     

    (Updated to remove pics - sorry new to this forum)

    GabrielSanchez
    New Member
    April 1, 2019

    I was having issues with remote accounts that have "Log On To" restrictions in AD (Consultants).

     

    The solution was to add a DNS host entry for the FG host name and add the FG name to the computers the user is allowed to logon. 

     

    For example;

     

    System->Setting

        Host name: MyFirewall

     

    Network->Interfaces

         Port 1: 172.1.1.1/24   (This is my LAN interface that talks to AD - LDAP)

     

    In my DNS server (AD), I added a host record;

        MyFireall   --> 172.1.1.1

     

    in Users And Computers (AD) I added "MyFirewall" to the "Log On To" list ( Open user in AD, go to the Account tab to find the option)

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!