Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
doncacciatoconsuting
Contributor

FSSO vs LDAP groups in Firewall Policy

Looking into the benefits of FSSO in our environment for the purposes of restricting internet access. What does FSSO give you that a simple LDAP group doesn't within a firewall policy ? Or are they to be used in conjunction ? 

 

Thanks all!

1 Solution
AEK
SuperUser
SuperUser

FSSO is for passive authentication, i.e.: once user opens a Windows session, he doesn't need to authentication again in order to be allowed.

Using LDAP group (created statically on FGT) should be associated with an active authentication in order to work, like active portal.

AEK

View solution in original post

AEK
1 REPLY 1
AEK
SuperUser
SuperUser

FSSO is for passive authentication, i.e.: once user opens a Windows session, he doesn't need to authentication again in order to be allowed.

Using LDAP group (created statically on FGT) should be associated with an active authentication in order to work, like active portal.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors