FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
khoffman
Staff
Staff
Article Id 227553
Description This article explains how to import admin user configurations from an LDAP group, as well as how to apply Admin Profile Mapping.
Scope FortiNAC 9.x
Solution

LDAP directory configuration and Admin Profile Mappings should be configured prior to completing the steps below.

 

Under Network> Settings > Authentication > LDAP

  1. Double-click on the directory.
  2. Select Search Branches.
  3. Configure a group search branch mapping.

Under System > Scheduler

  1. Select Synchronize Users with Directory.
  2. Select the Run Now button.

Under Network > Settings > Authentication > LDAP

  1. Double-click on the directory.
  2. Select the Select Groups tab.
  3. Place a check mark in the group to give administrative privileges to.

Under System > Scheduler

  1. Select Synchronize Users with Directory.
  2. Select the Run Now button.

Under System > Groups

  1. Delete the group (because it was imported as a host group).
  2. Add a group with the exact same name (case sensitive).
  3. Select the group type Administrator.

Under Users & Hosts >  Administrators

  1. Select Profile Mappings.
  2. Select Add.
  3. Use the drop-down menu to select the intended admin profile to give to the group.
  4. Use the drop-down menu to select the intended group to give privileges to.
  5. Select the Ok button.

Under System > Scheduler

  1. Select Synchronize Users with Directory.
  2. Select the Run Now button.