Does the new settings in 6.2 directly replaces LDAP Nested Group settings in 5.6
Does config gets upgraded (on firmware upgrade) or one needs to remove old settings & replace them with new MANUALLY?
Seb
Hi Seb,
as you might get tested by yourself, then: - it is NOT full replacement of group filter, as new option 'search-type recursive' will NOT return built-in user groups from AD - firmware upgrade will NOT update and replace your custom group-filter with 'search-type recursive', however there is no need to panic as your old group-filter will still work in 6.2. If you want to change, you'll need to do it manually. Retested on 6.0.4 and 6.2.0 and FortiGate VM upgraded via FortiGuard. Thanks for hint, I'll start with upgrade of the KB.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Sorry, could you clarify? - "will NOT return built-in user groups from AD" - you do mean literally AD built-in user groups
Which itself is not an issue (I expect for anybody), as none of these groups would be used for webfiltering etc)
But it does return all user custom-made groups, right?
Seb
Hi Seb,
yes I mean none of AD Builtin user groups like 'Remote Desktop Users' is returned with search-type = recursive, while those are returned with group-filter mentioned in KB. I also do not think it's a big issue as most often deployments do use custom groups to categorize users to access right groups and all those, including nested groups, are returned OK.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.