Users belonging to multiple AD groups
I have a Fortigate 90D with firmware 5.4.1. I am new to the Fortigate firewalls. My problem is the following:
I have two Active Directory groups called FacebookUsers and TwitterUsers. SSO is correctly configured.
So, I’ve set up this rules for testing purposes:
1- Allow rule, from internal interface to external, all services, all destination addresses, all source addresses and FacebookUsers group. I’ve attached a web filter profile called “Allow Facebook” with a static URL filter for the *.facebook.com wildcard domain set to allow. I’ve also assigned an SSL inspection profile.
2- Similar rule to allow Twitter with a web filter profile for the *.twitter.com wildcard domain.
3- Deny rule, from internal interface to external, all services, all destination addresses, all users, no web filter profile.
A user who belongs to the group FacebookUsers can browse the Facebook domain. But he can also browse Twitter and any other URL. Rule number 1 is applied.
A user who belongs to the group TwitterUsers can browse the Twitter domain. But he can also browse Facebook domain and any other URL. Rule number 2 is applied.
A user who does not belong to any of those groups is denied access and cannot browse any page.
The expected behavior should be that any user who belongs to the FacebookUsers group should be granted access to the Facebook page and any user who belongs to the TwitterUsers group should be allowed to access the Twitter page and any user who does not belong to any of those groups should be denied access to every page. However, a user who belongs to both groups should be allowed to access both sites.
This is just a simplified version of my real scenario which includes groups for granting access to other services such as YouTube, Streaming, Spotify and so on.
Can anyone please point me in the right direction to get the desired result?
Thank you all.
