Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
robinh007
New Contributor III

Centralized LDAP-Based Authentication for macOS native VPN Clients

Hi,

 

Is it possible to set up FortiGate to authenticate macOS native IPsec VPN clients through Active Directory, without requiring the Macs to be joined to the domain? 

 

Our goal is to remove local user accounts from FortiGate and transition macOS users to centralized authentication using LDAP, just like we do for Windows users.

 

 

FortiGate 

RH007
RH007
3 REPLIES 3
Stephen_G
Moderator
Moderator

Hello robinh007,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

If anyone else has any knowledge in this area - please feel free to contribute!

 

Thanks,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

In the meantime, if anyone else has any advice to contribute, please feel free to do so!

 

Thanks,

Stephen - Fortinet Community Team
Yurisk
SuperUser
SuperUser

Hi, I don't see why it would not work - authentication is happening between Fortigate and LDAP server, Forticlient (FC) (MacOS or not) just gets a reply from the FGT - authenticated or not, FC is not aware of the backend authentication method. Provided you are trying to authenticate against Windows LDAP. 

This should work: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Remote-Access-IPSEC-VPN-with-LDAP-authenti... 

https://yurisk.info
https://yurisk.info
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors