Hello everyone,
I setup a FortiNAC (with FortiGate, FortiSwitch and FortiAP) and the basic 802.1x and MAB authentication is working fine.
But now I want to return a specific VLAN ID based on the AD group membership of a device or user.
I can import AD groups to the FortiNAC but no members are displayed.
How am I doing this?
Thanks in advance
Mokka
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The AD groups will be auto populated when a Host will have an Registered User from that AD group. If you manually "Register Host to User" and type on of the User ID part of an AD group you have synchronised, it will show as member in the groups. This should be for testing, usually you have to configure some automatic procedure for this like the PA.
After that you can select this groups on "User/Host Profile" on the field "Who/What by Group:" or by using the Host Role that can be mapped in Policy & Objects > Roles
Hello emirjon,
thanks for your reply.
For user this is fine - but what about maschines? Is there an option to check the group membership of a computer object in the AD?
Thanks in advance
Best regards
Mokka
Hi, actually yes. You can pull them and it will show like this:
but I haven't test them on Roles to generate Roles based on this groups.
If you plan to dedicate the LDAP to Computers group only, maybe it's better to change the Object class from "user" to "Computer" and the other fields accordingly.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.