Created on
09-18-2019
06:20 AM
Edited on
09-28-2023
06:49 AM
By
Jean-Philippe_P
Description
This article describes the steps to configure the LDAP server in FortiGate and how to map LDAP users/groups to Firewall policies.
End users can then see a firewall popup on the browser that will ask for authentication prior to using the service.
Note that such a policy will also not allow DNS queries if the user is not authenticated.
End users must have some way of resolving the destination address that would match this policy.
If DNS does not work, the users will not be able to authenticate as the HTTP connection to the destination cannot be made.
Scope
FortiGate.
Solution
To configure the FortiGate unit for LDAP authentication – Using GUI:
For new Firmware 7.0 & above the path would be:
cn is the default, and most of the customers will be using sAMAccountName.
Make sure to get the info on which attributes the end users are using against the LDAP server as the values of the attributes can look different, for example, 'usert' vs. 'TestUser'.
For a Distinguished name, select browse and select the main domain (Select the domain once the Username and Password are entered as per steps 8 and 9).
In Bind Type, select Regular.
In the Username field, enter the LDAP administrator's account name along with the domain (Ref. Screenshot below).
In the Password field, enter the LDAP administrator's account password.
Select OK.
For new Firmware 7.0 & above the path would be:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.