Skip to main content
megaali3000
New Member
June 20, 2020
Question

Two separate groups in AD, with two internet uplinks?

  • June 20, 2020
  • 2 replies
  • 2518 views
Good day everyone,

we have an active directory with FSSO agent installed on it and two groups inside it, for example Group1 and Group2. and we have two internet connected to our fortigate interfaces.

now we want to restrict the groups to use only one exact internet (Group 1 ---> internet1, Group2 ---> internet2) and if one of the links disconnected we want the group that their internet was shut, switch to to connected link automatically.

And the problem is the users might logon to their pc anywhere in the network so I don't think using policy routes would help us.

I would be glad to hear your suggestions.

 

2 replies

Nikhil_Chaudhari
New Member
June 22, 2020

Hi,

you can achieve this via sd-wan rules by configuring sd-wan on firewall.

megaali3000
New Member
June 22, 2020

nklchdr wrote:

Hi,

you can achieve this via sd-wan rules by configuring sd-wan on firewall.

No the problem is SD-WAN doesn't support FSSO groups, and you don't have the ability to restrict a group to only use one internet link.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!