Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CyberFortiConquer
New Contributor II

CPPM integration for user-based rules

I am currently looking at integrating FortiManager (7.2.x) and ClearPass for user/identity based policies.

I have been looking at previous posts and and following admin guide from FortiManager, but there is very less info. Has anyone done this successfully in 7.x version? Also, does that work as expected? 
Many thanks.

 
 
4 REPLIES 4
ebilcari
Staff
Staff

Have you followed the steps shown here? This document is also mentioned to be helpful.

There are cases of successful integration, are you facing any particular error?

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ramenez1
New Contributor

That sounds right and looks more like what I thought. The test rules we created were called SilverPeak Orchestrator Login/Logout in CPPM and that really did not make much sense why that would be the only flows that would show the information. SP has made life a lot better here. Appreciate the reply.

10.0.0.0.1 192.168.1.254
CyberFortiConquer
New Contributor II

Thanks, yes I had followed that guide and it was very useful.

However, we were concerned about the number of roles that would need to be created per user.

ClearPass would usually dynamically assign multiple roles per user and have enforcement profiles depending on the roles, however FMG only captures the 1st role. Also there is issue with re-auth not being recognized.

Is it possible to integrate ClearPass with Fortinet directly via RSSO and create user-based rules off that?

For instance, User from group X allow to access Finance server, user from group Y allow to access HR server, but other users {NOT(X+Y)} cannot access Finance or HR servers.

ebilcari

Yes, you can use RSSO directly in FGT but the FGT configuration is a bit limited (not customizable), you have to test if it works directly with CPPM accounting messages content.

FortiAuthenticator offers a more flexible way of parsing the RADIUS accounting messages that can be later pushed to FGTs as SSO:

FAC.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors