Skip to main content
peterjhd1218
New Member
September 10, 2019
Solved

VPN with LDAP authentification

  • September 10, 2019
  • 1 reply
  • 4247 views

Hi, i gotta a question when an user is member of two LDAP groups and both groups has different portal in teh SSL VPN, each one with different range of addres.

My question is, when the user log in, to which group belong?

 

REgards

Best answer by Elthon_Abreu

Can you send a print from your "ssl.root > internal" rules?

1 reply

Elthon_Abreu
New Member
September 18, 2019

The Fortigate will follow the "top-down" rule... So, if the policy that allows "Group A" is above the policy from "Group B", your user will login by the Group A settings.

 

BR,

peterjhd1218
New Member
September 24, 2019

hi Elthon Abreu, thanks for your reply but still it´s not clear to my, let me get this right, i have two diferent SSL portal each one with different address range, according to you answer teh user will be log in with the first policy match that have one of the group that the user belong. 

Elthon_Abreu
New Member
September 24, 2019

Can you send a print from your "ssl.root > internal" rules?