FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Oscar_Wee
Staff
Staff
Article Id 395826
Description This article explains why it is not a good practice to use a group name as a name for a user.
Scope FortiGate.
Solution

 

incorrect creds.jpg

 

  1. For example, an admin created a username, 'Application', to denote a user who uses a certain application.
  2. Subsequently, the admin creates a new group called Application as well, with some users in it, namely 'A' and 'B'.
  3. The admin did not remove the user name 'Application' from the existing firewall policy due to oversight.
  4. 'A' entered the correct user name and password many times, but sees the error message that wrong credentials were entered.
  5. Admin skimmed through the existing firewall policy again and thought that the correct group 'Application' was used when in fact the user name 'Application' was used.
  6. However, on deeper examination, Admin realized that the correct group 'Application' has not been correctly configured into the firewall policy.
  7. On configuring the correct group 'Application' with 'A' and 'B' into the existing firewall policy. 'A' can authenticate successfully.
  8. Admin removed the user named 'Application' to avoid future potential mix-up.
Contributors