Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Philipp
New Contributor

FortiOS 5.2.2 - Web Filter precedence with membership to multiple groups

Hi everyone,

 

we are using explicit proxies with an FSSO Collector Agent to authenticate the windows AD users.

 

User test is member of group 1 which allows access to standard set of categories (e.g. shopping and auctions is blocked). Additional to that we would like to add the AD user to group 2 which only allows the access to the category shopping and auctions.

 

So finally we would like to have an user which is in group 1 and group 2 which has the access to the standard set of categories + the category shopping and auctions.

 

Is this scenario now possible with the current FortiOS version 5.2.2?

 

Cheers.

 

Philipp

2 REPLIES 2
Dave_Hall
Honored Contributor

Philipp wrote:

So finally we would like to have an user which is in group 1 and group 2 which has the access to the standard set of categories + the category shopping and auctions.

 

Is this scenario now possible with the current FortiOS version 5.2.2?

 

See the 5.2.0 patch notes (page 16) regarding Implicit fall-through feature for user authentication policies.

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Philipp
New Contributor

Thanks for your reply.

 

I'm not sure but I think this is not possible with a explicit proxy and AD groups?

Is this correct?

Labels
Top Kudoed Authors