Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AndersonGodoy
New Contributor

FSSO works with Samba4 AD mode?

Hello, I am running a test lab, where I configured a samba 4.7.6 in AD mode and am trying to perform samba integration with the fortigate to work with SSO authentication. However all the documentation I found for the fortigate or for the authenticator was for integration with Windows Active Directory. Is there a way, or does anyone know of any way to configure FSSO with Samba, either by Fortigate or Fortiauthenticator or with any Fortinet product?

8 REPLIES 8
levan68
New Contributor

integrate samba4 AD with fortigate is posible , i have running a test lab  FSSO with samba4 ad , i just add command " ldap server require strong auth = no " in smb.conf  and run this step 

http://help.fortinet.com/...tion/SSO-WindowsAD.htm

AndersonGodoy

Hi @levan68

 

Thanks for your reply, i will test this guide. Do you had any problem that you remember? besides this option "ldap server strong auth" that i already use on my smb.conf.

bommi

Hi AndersonGodoy,

 

have you been able to setup FSSO with Samba4?

My setup using Samba 4.9.4 doesn't work.

 

Regards

bommi

NSE 4/5/7

NSE 4/5/7
AndersonGodoy

Hi bommi,

 

unfortunately no, no SSO configuration with samba4 worked, even following all cookbooks.

bommi

Thank you for your response!

 

I will try the Palo Alto way using Syslog SSO, but in this case I need to use FortiAuthenticator to read the syslog messages from Samba4 and to build the user database.

 

This is how Palo Alto PanOS does it:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRhCAK

 

As the FortiGate itself cant be configured to read the syslog messages, we need an FortiAuthenticator:

http://help.fortinet.com/fauth/4-0/Content/4_0%20Admin%20Guide/600/607_Syslog.htm

 

Regards

bommi

 

NSE 4/5/7

NSE 4/5/7
romanr
Valued Contributor

Hi,

 

no Fortinet FSSO technique will work with Samba 4AD. Just because the Fortinet SSO solution will read windows event logs or run WMI calls to the domain controllers to discover logged on users and their IPs.

 

Using Syslog SSO with FAC can be a proper way to achieve your goals.

 

Depending on your needs you could also consider Kerberos based Authentication for your users with explicit or implicit proxy configuration.

 

Br,

Roman

meavric
New Contributor

Hello,

Do you found any answer how connect samba with FG?

BR

bommi
Contributor III

Hello,

 

there is no direct integration possible between the fortigate and samba4.

You would need to send the samba logs using syslog to an FortiAuthenticator.

The FortiAuthenticator then reads the login and logoff events and builds an fsso database which is shared with the fortigate.

 

BR

bommi

NSE 4/5/7

NSE 4/5/7
Labels
Top Kudoed Authors