FortiPAM
FortiPAM allows you to protect, isolate and secure privileged account credentials, manage and control privileged user access, and monitor and record privileged account activity.
sfernando
Staff
Staff
Article Id 407961
Description This article discusses a limitation of using Web Launcher in FortiPAM.
Scope FortiPAM v1.7 and older.
Solution

Web launcher is one of the options used to access the targets in FortiPAM. This uses an HTTP/HTTPS browser extension to access the HTTP/HTTPS resource.

 

It is mandatory to enable 'explicit-web-proxy' under the interface where the resource is accessed. Refer to this document: Web proxy

 

config system interface
   edit "port1"
      set explicit-web-proxy enable <----- Must be enabled.
   next
end

 

In different circumstances, users may need to enable this feature in different interfaces to access different targets based on the network setup.

 

'explicit-web-proxy' feature can be used only on a single interface, limiting all the web launchers in the setup to use just one interface.

In GUI, it is not possible to enable 'explicit-web-proxy' on 2 interfaces, and it will give an error as below. However, in CLI, it is possible to enable it on multiple interfaces, and it will be shown on the GUI as well.

 

When it comes to operation, only one interface will work with 'explicit-web-proxy'. This will result in abnormal behavior in the function of Web Launcher, resulting in intermittent working and not on a particular interface.

 

EWPen.jpg

 

EWPdis.jpg

 

This limitation will be addressed in future releases.

Contributors