Hi guys,
My infra consist of hundreds VDI(citrix) & VM(VMware). And my fortigate not not applied with FSSO. The issue here is, how can I block facebook for some users that using VDI(IP address and hostname change everytime users login)?
Thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
You have 2 options:
- Use explict web proxy with Session basead authentication
or
- Search for FSSO for Citrix
http://docs.fortinet.com/uploaded/files/1937/fortigate-authentication-52.pdf
Regards,
Paulo R.
Regards, Paulo Raponi
Hi,
i think you will be asked for more things to block. So in your position i would config both, webproxy and FSSO.
works fine for me. Just a few hints:
- Install Fortinet collector agent on DC
- Install Terminal Server Agent on Terminal server
Don´t use the other methods such as reading from the AD or getting pushed updates from DC to a seperate maschine. don´t worked for me very good.
Regards
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.