Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Carl_Windsor_FTNT

FortiAuthenticator 3.1

Fortinet are pleased to announce that FortiAuthenticator 3.1.0 (build 0060) has been approved for General Availability (GA). Updated release notes are available on the Support site https://support.fortinet.com for download. This is a feature release containing (but not limited to) the following key features: • Secondary/Fallback LDAP server • Proxy authentication to external RADIUS Server • Support Authentication to multiple domains (realms) • FortiToken Mobile Rebranding • Administrator Access Control • Enhancement to the API for Token Assignment • User Token Management Enhancements • Support User and Machine Auth for PEAP/TTLS/TLS • Support for Kerberos User ID via Authentication Portal • Improved User Certificate Management Workflow For full details of the changes, please see the Release Notes and What' s New Guides http://docs.fortinet.com/fortiauthenticator/ for more detail. Solutions Guides will be updated to reflect 3.1 changes in the coming weeks.

Dr. Carl Windsor Field Chief Technology Officer Fortinet

10 REPLIES 10
Silver
New Contributor

Anyone has setup fortiauthenticator using external database windows Active directory for single sign on to work with fortigate.
Carl_Windsor_FTNT

ORIGINAL: Silver Anyone has setup fortiauthenticator using external database windows Active directory for single sign on to work with fortigate.
We have a large number of deployments gathering login information from AD. We have several ways to collect login information from AD including: • Polling login info • DC Agent installed on the DC • Single Sign on Mobility Agent • Kerberos • Manual Authentication with widget

Dr. Carl Windsor Field Chief Technology Officer Fortinet

Matthew_Mollenhauer
New Contributor III

We don' t have our FAC' s doing authentication, but we do have our switches (doing 802.1x) sending Accounting Records to our FAC' s, which are then doing AD Group Membership lookups. We' re then forwarding those SSO records to our Fortigates. It works great very well, though you' d need to ensure you get QoS working if we' re sending radius over a WAN. Regards, Matthew
Silver
New Contributor

Hello is the setup possible what i mentioned in the post!!!! Thanks
Carl_Windsor_FTNT

ORIGINAL: Silver Hello is the setup possible what i mentioned in the post!!!!
Fortinet Single Sign on for FGT IBP with AD is fully supported by FAC. I gave examples of various methods in my previous post.

Dr. Carl Windsor Field Chief Technology Officer Fortinet

Silver
New Contributor

can you provide me a doc explain step by step how to configure!!! Thanks
Carl_Windsor_FTNT

You will find the FortiAuthenticator FSSO Auth Methods Guide on the docs site here. http://docs.fortinet.com/d/fortiauthenticator-fsso-authentication-methods-configuration-guide-1 We are working on updating it for 3.1 to include Kerberos and other new features so keep an eye on the docs site over the coming week.

Dr. Carl Windsor Field Chief Technology Officer Fortinet

Carl_Windsor_FTNT

Correction. here is the link to the 3.0 version. http://docs.fortinet.com/d/fortiauthenticator-3.0-fsso-authentication-configuration-guide

Dr. Carl Windsor Field Chief Technology Officer Fortinet

neonbit
Valued Contributor

I have a FortiAuthenticator running and sync' d with an AD network that provides SSO for my FortiGate. It works well and is easy to setup. One thing that caught me out when I upgraded to 3.1 was that you can' t configure a remote user to be available for RADIUS requests as well as being the local admin for the Authenticator. It has to be one or the other (previously you could have both). For example, I have a user called ' neonbit' imported into the Authenticator from AD. The user is flagged as an admin, so he can log into the Authenticator as a administrator using his AD credentials. If I then want the Authenticator to provide RADIUS authentication to my FortiGates admin login, then I can' t login to the FortiGate with the user ' neonbit' . This caught me out a little as none of our admin users were able to login to any of the Fortinet devices any-more. Luckily we had a local admin configured on the Authenticator and were able to sorted it out. p.s: The realms addition is excellent!
Labels
Top Kudoed Authors