Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sean_powell
New Contributor

FSSO and Mac

We have a few Macs in our fold, and the users who use them don' t show up in FSSO in the logs. Windows users show up fine. Is there a way to get our mac users to show up as FSSO users? eg. windows users browsing the web show up as First_lastname, but if on a mac it just shows up as an IP address which we can' t really track against all the other traffic. thanks
5 REPLIES 5
billp
Contributor

We use LDAP authentication. Our Mac users login via web authentication and show up under their LDAP user name in logs. If a user is already logged in via FSSO, they don' t get the web auth screen.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
square20
New Contributor

Hi Bill, It sounds like you are using FSSO and LDAP (web page logon for Macs) together, is that right? Do you use the keep-alive option on the web-auth screen? Do you have separate policy rules for the windows computers, and the Macs - or do you have them both matching one rule -with both authentication options configured? We tried having a single rule for PCs (FSSO) and Macs (web auth) but we found the windows users were getting the web auth screen too. How did you solve this? Thanks Paul
cheaman
New Contributor II

Are you using Active Directory and are your Macs on the domain? If so, put your FSSO in polling mode and click the " Check Windows Security Evernt Logs" radio button. Works perfectly.
Fortigate 1240B FAZ 4000A
Fortigate 1240B FAZ 4000A
billp
Contributor

Paul, I am using eDirectory, not Active Directory. That might be the difference here. We have a single policy rule but it should be operationally similar to what you have. Our Macs are not using our directory service (other than LDAP for login). With our FSSO setup, the firewall first checks the FSSO server to see if the IP address of the workstation has logged into the directory service. If so, it grants them access per their assigned group membership. Otherwise it presents the web login screen for LDAP. Cheaman' s solution sounds pretty good if your Macs are logging into AD.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
square20
New Contributor

Hi Bill, Thanks for the quick reply. That sounds similar to what I tried. We use AD for FSSO, and then LDAP for web page logon. Does your single policy have something like this, with two auth groups? When your Mac users log on via the web page, do they then get the keep-alive window - or is it just one page with a web logon form? Thanks, Paul
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors