We are working on deploying firewall to 6 locations and using FAC to handle our WiFi cert based Auth this is for users who migrate across the 6 locations and FSSO to create user based policy's for users that are local to one of the 6 locations. I have been to get one or the other to work but not both at the same time. It seems the firewalls will only query the first active connection in the "remote auth" list. If FSSO is first it will use that one but will never look to the FAC and vise versa can anyone offer any suggestions om how to address this issue? or am i going to have to shell out more money to buy enough users licenses to push all the auth request to the FAC device?
Hello,
in FSSO scenario FAC act as Collector (similarly but not exactly same as standalone FSSO Colelctor). Therefore FSSO user list is pushed to connected FGT units according to group filters etc set on FAC. There is nothing like active query to FAC when user is trying to pass FSSO based identity policy (except it's NTLM type of auth).
So FAC as FSSO Collector has to know users first, then it can collect group membership from connected DC and push results to connected FGT units.
Not sure where your WiFi users authenticate. If they do some RADIUS auth (for example WPA2 Enterprise over RADIUS) then this RADIUS server maybe can send RADIUS Accounting packet to FAC which can gather the data from RADIUS AAA and make FSSO record based on the data (similar to RSSO on FGT).
I'd suggest to do either or both:
* go docs.fortinet.com and check wifi implementation guide, cookbooks, FAC admin guide, FGT Authentication guide
* open ticket on tech support
* ask Fortinet SalesEngineer for help or Fortinet ProfesionalServices team(s) for help with implementation
Best regards, Tomas
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.