Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
I'm sorry but 'biometric' is ... ?? - your user name
- your workstation name
- you are member of the group with this name
- second factor in authentication, via some device
It is good if question is simple, but it still need to have enough info, so other can provide more or less simple answer.
In general, if it is any sort of second factor authentication, like FortiToken, then it usually needs to be active authentication on FortiGate.
However if that biometric second factor is supposed to be handled by Microsoft's AD, then your logon with such feature is most probably handled completely by AD and one of respective Domain Controllers. And then such logon can be seen by FSSO and reported to FortiGate. In this case biometric does not play any role from FortiGate's perspective, as we should get info about logged on user when he succeeds against DC. Logon on DC is completely out of our scope. If logon is OK but there is no FSSO user on FortiGate, then most often such user do not belong to AD user groups monitored by FSSO.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hello dear
How is that ESSL integrated with AD?
User touches it and then?
What does the system send and to where.
Best Regards,
Alivo
livo
Add a new rule above the authentication rules, specifying the Biometric Server IP that needs to talk out and don't add users/groups to that rule. Now the bio server should have internet access without needing to go through authentication.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.