Skip to main content
Vishalv16
New Member
November 8, 2019
Question

wan to block computer getting internet access via FSSO client on AD to fortigate

  • November 8, 2019
  • 1 reply
  • 2242 views

I have system that i want to set ip base internet policy which will be time base, now apart form that time limit any user who are in domain can login to system but should not able to access internet. is there any way that i can do from AD FSSO client or from fortigate (note: this is already there but i want to know how they did that) no ip is block on fortigate also changing ip address was no use thanks in adavance Vishal

    1 reply

    xsilver_FTNT
    Staff
    Staff
    November 12, 2019

    Hi Vishal,

    not sure I understand your needs.

     

    FSSO IS IP based, it is not session based, unless you use Collector for NTLM.

    Keep in mind that pure IP based policies (no user groups, in short) has priority before Identity based policies.

    Time schedules should work for both types.

     

    Unless your DCs are behind firewall, from network/policy perspective (so no traffic/forward policy govern access from PC to DC), then logon to domain should always work.

     

    FortiGate is implicit deny-any type of firewall. So policies are exemptions allowing access under specific conditions, like time, source/destination address/port, services and user/device identity.

    So to achieve identity driven access avoid any pure IP based policies without user group bond.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!