FortiPAM
FortiPAM allows you to protect, isolate and secure privileged account credentials, manage and control privileged user access, and monitor and record privileged account activity.
mturic
Staff & Editor
Staff & Editor
Article Id 345192
Description This article clarifies the possible authentication methods used for connecting to VNC servers via FortiPAM.
Scope FortiPAM v1.x.
Solution

FortiPAM supports connections to VNC servers on various platforms, such as MacOS, Windows and Linux, with different authentication capabilities.

 

MacOS:

  • VNC password authentication (password defined in the VNC server itself)
  • MacOS user credentials (username and password used to log in to MacOS, without needing to enter the VNC password specifically)

Windows:

  • VNC password authentication (password defined in the VNC server itself; after connecting, the target host might still require Windows user credentials for login)

Linux:

  • VNC password authentication (password defined in the VNC server itself; after connecting, the target host might still require Linux user credentials for login)

 

Note:

  • FortiPAM supports VNC via built in launchers as VNC Viewer, Tight VNC and web-based opens (Web VNC)
  • Capture on FortiPAM will confirm on the security types supported and the response from the client

Troubleshooting debug commands that can be handy:

 

diagnose debug console timestamp enable
diagnose wad debug enable category auth
diagnose wad debug enable category secret
diagnose wad debug enable level verbose
diagnose wad debug enable category vnc

 

  • To take a packet capture, follow GUI Packet capture.
  • Security type on the capture will be presented and selected by the client.

 

VNC1.png

 VNC2.png