Hello, I want to create specific access rule per one user from AD
While selecting source, and user, I get error
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
It works for the single user (accessing from any source IP included by adding address object "all").
best regards,
Jin
when I try to configure policies, I select "all" address object, specific user added from Remote LDAP users, but all traffic goes to the below policy and not matching on that policy, where I have user in source.
what can I do further?
Policies with Accept action will take precedence over policies that have users specified. More details are shown in this article here.
to use AD Users or AD UserGroups in Policies you must have a working AD Fabric connector and an FSSO CollectorAgent on every Domaincontroller.
This is needed to read the Structure of the AD to provide users and groups (Fabric connector) and to poll AD Logon events (CollectorAgent) because that is the only way to determine the currently logged in user on a machine in AD.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hi @lrazmadze,
To use AD group in firewall policies, you need to configure FSSO. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-FSSO-in-DC-Agent-mode/ta-p/25299...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.