Hello, I am running a test lab, where I configured a samba 4.7.6 in AD mode and am trying to perform samba integration with the fortigate to work with SSO authentication. However all the documentation I found for the fortigate or for the authenticator was for integration with Windows Active Directory. Is there a way, or does anyone know of any way to configure FSSO with Samba, either by Fortigate or Fortiauthenticator or with any Fortinet product?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
integrate samba4 AD with fortigate is posible , i have running a test lab FSSO with samba4 ad , i just add command " ldap server require strong auth = no " in smb.conf and run this step
Hi @levan68
Thanks for your reply, i will test this guide. Do you had any problem that you remember? besides this option "ldap server strong auth" that i already use on my smb.conf.
Hi AndersonGodoy,
have you been able to setup FSSO with Samba4?
My setup using Samba 4.9.4 doesn't work.
Regards
bommi
NSE 4/5/7
Hi bommi,
unfortunately no, no SSO configuration with samba4 worked, even following all cookbooks.
Thank you for your response!
I will try the Palo Alto way using Syslog SSO, but in this case I need to use FortiAuthenticator to read the syslog messages from Samba4 and to build the user database.
This is how Palo Alto PanOS does it:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRhCAK
As the FortiGate itself cant be configured to read the syslog messages, we need an FortiAuthenticator:
http://help.fortinet.com/fauth/4-0/Content/4_0%20Admin%20Guide/600/607_Syslog.htm
Regards
bommi
NSE 4/5/7
Hi,
no Fortinet FSSO technique will work with Samba 4AD. Just because the Fortinet SSO solution will read windows event logs or run WMI calls to the domain controllers to discover logged on users and their IPs.
Using Syslog SSO with FAC can be a proper way to achieve your goals.
Depending on your needs you could also consider Kerberos based Authentication for your users with explicit or implicit proxy configuration.
Br,
Roman
Hello,
Do you found any answer how connect samba with FG?
BR
Hello,
there is no direct integration possible between the fortigate and samba4.
You would need to send the samba logs using syslog to an FortiAuthenticator.
The FortiAuthenticator then reads the login and logoff events and builds an fsso database which is shared with the fortigate.
BR
bommi
NSE 4/5/7
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1721 | |
1098 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.