I am currently looking at integrating FortiManager (7.2.x) and ClearPass for user/identity based policies.
I have been looking at previous posts and and following admin guide from FortiManager, but there is very less info. Has anyone done this successfully in 7.x version? Also, does that work as expected?
Many thanks.
That sounds right and looks more like what I thought. The test rules we created were called SilverPeak Orchestrator Login/Logout in CPPM and that really did not make much sense why that would be the only flows that would show the information. SP has made life a lot better here. Appreciate the reply.
Thanks, yes I had followed that guide and it was very useful.
However, we were concerned about the number of roles that would need to be created per user.
ClearPass would usually dynamically assign multiple roles per user and have enforcement profiles depending on the roles, however FMG only captures the 1st role. Also there is issue with re-auth not being recognized.
Is it possible to integrate ClearPass with Fortinet directly via RSSO and create user-based rules off that?
For instance, User from group X allow to access Finance server, user from group Y allow to access HR server, but other users {NOT(X+Y)} cannot access Finance or HR servers.
Created on 05-22-2024 03:45 AM Edited on 05-22-2024 03:46 AM
Yes, you can use RSSO directly in FGT but the FGT configuration is a bit limited (not customizable), you have to test if it works directly with CPPM accounting messages content.
FortiAuthenticator offers a more flexible way of parsing the RADIUS accounting messages that can be later pushed to FGTs as SSO:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1735 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.