Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BarryGhuman
New Contributor II

FortiNAC - LDAP user group

Hi Team,

 

I am swapping from Cisco ISE to FortiNAC.

 

Currently, ISE permits access with EAP-TLS and LDAP user groups (Domain users and domain computers)

 

In FortiNAC, EAP-TLS authentication is possible but I don't see any option to permit access based on user/computer account at LDAP/AD. 

 

Regards, 

Barry Ghuman

 

 

Barinder Ghuman
Barinder Ghuman
7 REPLIES 7
AEK
SuperUser
SuperUser

Hello Barry

Do you mean your user-host policy is not assigning the right network to your clients?

AEK
AEK
BarryGhuman
New Contributor II

I must assign the network to the users based on their username (fetched from the EAP-TLS certificate CN or SAN). 

 

I don't see any option in FortiNAC that maps "Network Access" based on the LDAP group membership. 

 

For Example: 

Workstation (logical Network) - EAP-TLS (machine auth & Domain Computers)

Users (logical Network) - EAP-TLS (user auth & Domain Users)

 

Barinder Ghuman
Barinder Ghuman
AEK
SuperUser
SuperUser

If I remember well I was used to achieve it by creating group (AD group/computer) under menu System > Groups, then I use it to define my UHP profile in field "who/what by group", then assign the right access rule to that UHP.

AEK
AEK
BarryGhuman
New Contributor II

Hi, I don't see anything in the NAC-F. Could you please confirm if the feature is still available?

Barinder Ghuman
Barinder Ghuman
Sx11

Hello @BarryGhuman ,

 

the LDAP group are populated with Users once they register to the host.

You can then use the LDAP group as matching filter in the User host profile in the "who/what" setting

https://docs.fortinet.com/document/fortinac-f/7.4.0/administration-guide/15797/user-host-profiles

 

 

Check this article to understand how LDAP groups are synched and populated in FortiNAC:

https://community.fortinet.com/t5/FortiNAC/Technical-Tip-What-causes-a-host-to-be-moved-to-an-import...

 

If the policy is not matching based on LDAP group check this for troubleshooting:

https://community.fortinet.com/t5/FortiNAC/Technical-Tip-User-not-matching-policy-requiring-LDAP-Gro...

 

You can also leverage computer objects and they Computer name will appear as "User" in FortiNAC.

Article:https://community.fortinet.com/t5/FortiNAC/Technical-Tip-Leveraging-Domain-Group-Membership-of-Clien...

 

Regards

sx11
AEK

AEK
Sx11

Just for information the newest release of FortiNAC 7.6 has now a dedicated guide for Machine authentication:

https://docs.fortinet.com/document/fortinac-f/7.6.0/machine-authentication/478932/overview

Authentication methods supporting EAP-MSCHAPV2 and EAP-TLS

sx11
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors