Web Filtering while utilizing the Fortinet SSO Agent - With multiple Fortigate Firewalls
I have a question about Web Filtering while utilizing the Fortinet SSO Agent (v5.0.287). We have a Fortigate perimeter firewall and the Fortinet SSO Agent is installed on both our primary and backup DCs. That configuration works as expected. However, we’re in the process of implementing an internal Fortigate firewall, which servers will eventually sit behind. During testing, we’ve found that all devices sitting behind the internal firewall default to the universal web filtering profile on the perimeter firewall. (The internal firewall has a web filter license, but it’s not enabled.) The Fortinet SSO Agent lists the test device/user in its Logon User List with the user’s correct AD web filter group, but that user’s web filter group is NOT recognized by the perimeter firewall. All other traffic in/out of the internal firewall is working at this point because there are no restrictions yet. We can ping and tracert in and out through the internal firewall, access internal network devices, and Internet access is there but limited because of the default web filter profile issue. Any ideas why web filtering is not working as expected when a device is behind the internal firewall?
