FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mle2802
Staff
Staff
Article Id 256558
Description

This article describes a case scenario where a user is bound to the wrong IP while authenticating using FSSO agentless polling mode.

mle2802_0-1684150633636.png

 


mle2802_1-1684150633642.png
Scope All firmware and FortiGate.
Solution

This behavior happens when the PC on which the user is logged in is located on a different network than the AD server and NAT is enabled on the policy between those networks.

With NAT enabled, it will be translated to the FortiGate interface IP instead. In this case, it is 10.1.1.1.

After disabling NAT on the internal policy between the AD server and the user network, the right IP will be shown.

mle2802_2-1684150652542.png

 


If the issue persists, contact Fortinet support.