Skip to main content
Baboda
New Member
August 25, 2015
Question

When is traffic identified as FSSO Guest ?

  • August 25, 2015
  • 1 reply
  • 5775 views

Hello,

I've got an issue with a user ldap authentication for about 10 minutes during which IP was recognized as guest user in FSSO_Guest_Users group. After user successfully turned in authentication guest disappeared. I've been reading the following doc http://kb.fortinet.com/kb/documentLink.do?externalID=FD35363 but it is not still evident to me the way guest user and related FSSO_Guest_Users works with no matching identity policy rules for guest or FSSO_Guest_Users group.

 

Thank you

    1 reply

    xsilver_FTNT
    Staff
    Staff
    August 27, 2015

    Hello,

    basically said, if FSSO Guest Group is used (usually as the last group) in FortiOS 5.0 or 4.3 Identity-based policy using FSSO.

    Then if users' traffic match that policy but user is not found/matching any record from FSSO user list (diagnose debug authd fsso list) , then user pass through FSSO Guest Group and his traffic is marked as from FSSO guest.

     

    Kind regards, Tomas