- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiNAC - LDAP user group
Hi Team,
I am swapping from Cisco ISE to FortiNAC.
Currently, ISE permits access with EAP-TLS and LDAP user groups (Domain users and domain computers)
In FortiNAC, EAP-TLS authentication is possible but I don't see any option to permit access based on user/computer account at LDAP/AD.
Regards,
Barry Ghuman
- Labels:
-
FortiNAC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Barry
Do you mean your user-host policy is not assigning the right network to your clients?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I must assign the network to the users based on their username (fetched from the EAP-TLS certificate CN or SAN).
I don't see any option in FortiNAC that maps "Network Access" based on the LDAP group membership.
For Example:
Workstation (logical Network) - EAP-TLS (machine auth & Domain Computers)
Users (logical Network) - EAP-TLS (user auth & Domain Users)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If I remember well I was used to achieve it by creating group (AD group/computer) under menu System > Groups, then I use it to define my UHP profile in field "who/what by group", then assign the right access rule to that UHP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, I don't see anything in the NAC-F. Could you please confirm if the feature is still available?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @BarryGhuman ,
the LDAP group are populated with Users once they register to the host.
You can then use the LDAP group as matching filter in the User host profile in the "who/what" setting
https://docs.fortinet.com/document/fortinac-f/7.4.0/administration-guide/15797/user-host-profiles
Check this article to understand how LDAP groups are synched and populated in FortiNAC:
If the policy is not matching based on LDAP group check this for troubleshooting:
You can also leverage computer objects and they Computer name will appear as "User" in FortiNAC.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I see it still exist on FNAC-F.
Here it is:
https://docs.fortinet.com/document/fortinac-f/7.4.0/administration-guide/781776/add-groups
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just for information the newest release of FortiNAC 7.6 has now a dedicated guide for Machine authentication:
https://docs.fortinet.com/document/fortinac-f/7.6.0/machine-authentication/478932/overview
Authentication methods supporting EAP-MSCHAPV2 and EAP-TLS
