Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fred3
New Contributor II

First time setup putting AD Usernames / Groups into Web Filters

We are introducing a Fortigate_80F for the first time in our networks.  This is a Windows Server based domain network.  We want to set up the Fortigate web filters to pick up usernames from AD Security Groups and assign names or groups to web filters.  Then, the objective is for each User to be treated by the same web filter structure no matter which workstation they may be logged into.

This appears to require two things:

1) Get the Groups / Names attached to the web filter rules in Fortigate.

2) Determine the matching Usernames from web accesses reaching the Fortigate.

How is this best done?

We don't want the Users to have to log into anything new or additional - just the domain at Windows logon.

I've gone through likely references and remain fairly lost.  But, suggested references would be appreciated.

10 REPLIES 10
fred3
New Contributor II

Progress has been a bit slow but I'm back on it now.  Some background and questions:

I've selected to install FSSO on each of the 3 DCs.  Not much done there yet.

The app is Fortinet Single Sign On Agent it appears.

Is there a good configuration guide for this app?

 

ONE DC (of 3) has had LDAPS set up.  Should I set up LDAPS on the other TWO DCs next before proceeding with FSSO?  I'm still a bit foggy re: Certificates since now it's been a while since I did the first setup (which seems to work - in a limited way).

 

Some of the things I'm reading from Fortinet mention "Collectors" and "Agents".

My understanding is that the FSSO Agent install on the DCs will take care of both.  So, when I read "Collector", I'm assuming that's a DC.  Right?  I don't see any specific Collector install with the method chosen.

Labels
Top Kudoed Authors