Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tony_Palma
New Contributor

FSSO Users with Multiple Groups and different security profiles

Hi everyone, I had a question about this scenery:

 

I obtain User's Logon/Logout with FSSO, my users of AD are on groups who are related one-to-one to Fortigate users groups.

 

So, I create a policy for every user groups, with their respective Security Policy for Application Control and Web Filter.

 

The problem became with users that had assigned two or more AD groups, because the order of Policies allow or deny(or reset for browser-based) applications and block URLs.

 

Theres any way to allow or deny not for precedence of the rules, but by another way?

 

One solution that I find, its to create a organizational hierarchy order of policies for groups (directors, aux, adm, etc).

 

Regards,

Kind Regards,

Kind Regards,
1 REPLY 1
rzagorodnev
New Contributor

Hi. I have the same situation. Are you find a solution?

Labels
Top Kudoed Authors