Created on 02-29-2024 12:06 AM Edited on 02-29-2024 12:06 AM By Anthony_E
Description | This article describes how to provide specific resource access to a particular user |
Scope | FortiGate. |
Solution |
The steps in this article assume the following setup:
The above configuration will allow user2 to access both the servers 10.86.9.42 & 10.86.9.78 whereas user1 will be access to only one server i.e. 10.86.9.78
Verification: commands for SSL VPN debug:
diag debug reset diag debug application sslvpn -1 diag debug application fnbamd -1 diag debug console timestamp enable diag debug enable
User1 SSL VPN debug:
[403] ldap_copy_grp_list-copied CN=user1grp,CN=Users,DC=dxblab,DC=local
[2308:root:2c]deconstruct_session_id:505 decode session id ok, user=[user1], group=[user1grp],authserver=[ldap_lab],portal=[user1_portal],host[10.5.23.237],realm=[],csrf_token=3831424BD2BB7A092DC1D7A646A6223],idx=0,auth=16,sid=45efc635,login=1709035789,access=1709035789,saml_logout_url=no,pip=90.83.10.129,grp_info=[TEPhGG],rmt_grp_info=[T0ChcK]
User1 PC - Route table output. There is only one entry for the server 10.86.9.78.
User2 SSL VPN debug:
[2401] fnbamd_ldap_result-Result for ldap svr 10.86.9.78(ldap_lab) is SUCCESS
[2308:root:38]deconstruct_session_id:505 decode session id ok, user=[user2], group=[user2grp],authserver=[ldap_lab],portal=[user2_portal],host[10.5.23.237],realm=[],csrf_token=[A5C4A7B556F535B3BF178A0379AA266],idx=0,auth=16,sid=1aafef0a,login=1709036468,access=1709036468,saml_logout_url=no,pip=90.83.10.129,grp_info=[uDvanK],rmt_grp_info=[Se1CxI]
User2 PC - Route table output. It is possible to see the route for both servers 10.86.9.78 and 10.86.9.42.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.