Hi all,
As I am relatively new to the subject, please ignore the simplicity of the question:
We have a fortigate 110C with 4.0 MR1 Patch7. Recently we installed the FSAE package on our MS-domain controllers to be able to alllow/block access based on AD-users or AD-groups (that is at least what I understand what should be able).
Now, if I configure a policy with the Identy Based Policy option activated, I can add a previously AD-group defined to have access to a certain service, for example HTTP/HTTPS.
However, all other users not belonging to the selected group are blocked to the HTTP/HTTPS service, while my expectation would be a fall through to the next policy, which would give me the same way of working with IP-based policies.
The group used in the Identity Based Policy option is a Directory Service group created through the User, User Group options that includes a group from the AD-server
Thanks in advance.