Hi Team,
We are implementing Explicit proxy at the customer end with Fortinet Firewall-601F. The scenario is we have two VDOM's i.e. Proxy and Perimeter. The user traffic will pass from Proxy towards Perimeter to reach the internet.
For user authentication, we are using FSSO. The challenge we are facing is that in FSSO only groups are calling rather than specific user. Our goal is to apply separate policies on the user. In FSSO, we have fetched the AD user locally via LDAP rather than collector agent. The problem is that we have got four active directory and in FSSO only one of them is allowed to add. A user can land on any of the Active Directory for the authentication whereas if any user landed on the active directory that is not part of the FSSO will not be able to authenticate.
So kindly help and advise, how can we resolve and overcome the said issue.
Moreover, please also let us know in Explicity proxy what is the recommendation either FSSO is more valuable or Kerberos.
Anybody can provide assistance on this?
User | Count |
---|---|
2640 | |
1400 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.