I am working on setting up FSSO via the direct polling method on our 500D (v5.2.4,build688) firewall. I have created LDAP connections and Single Sign-On profiles for each AD server (4 in total) all polling the same group. I then created a user group for the fsso binding. This pulls in user login/logoff info and I can see it constantly streaming through the user event log for all AD servers however when I add the user group our outgoing policy (as the cookbook says, see link below) I can no longer access the internet. Why is FSSO pulling but not letting me authenticate to the policy? I can provide any further info needed
http://cookbook.fortinet.com/fsso-polling-mode/
Hi, be aware that Fortigate first checks for 'normal' policies in its rulebase and then the identity based policies.
When you have an explicit deny configured, that rule is hit!
Check for policy processing via diag deb flow filter tool.
Kind regards,
Ralph Willemsen
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.