Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aironfabio
New Contributor

Firewall Policy checking AD Users

Hello Team,

 

I have a customer with a firewall policy that grants access to the internet based on membership in an AD Group.

The policy works fine except for when a user logs into their PC before connecting to the wifi - in this case the user connects to the network but Fortigate doesn't grant access to the Internet until the user locks and unlock their machine; sometimes the user doesn't even notice for an hour if they just check internal systems.

 

Is this working as intended or is there a way of checking the membership even after the first login?

 

thanks in advance

F.

1 REPLY 1
funkylicious
SuperUser
SuperUser

hi,

using FortiGate to retrieve from a DC agent or polling the AD directly ?

L.E. i think its related to event id 4624 not being trigger due to logon to the workstation before having network access to the DC.

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors