Hi Folks,
I would like to set up a Fortigate Firewall running 5.4.7 as an explicit proxy and have users authenticate by typing in their username and password. I want different A/D user groups to have different security profiles. So what I would like to do is just set up LDAP and use only LDAP authentication for the users. Can anyone tell me if this is possible? And if so which authentication method I should use in the proxy policy?
I could use FSSO but some devices are not on the domain, so I would rather just use LDAP credentials for the authentication. Any pointers appreciated.
Thanks, Moby.
Hi Moby,
This is possible but you will find the web page that requests the credentials is not served over HTTPS. This means your users' credentials (including password) will be sent over the network in plain text. I consider that to be a massive short fall.
I found this article http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-WAN-opt-54/web_proxy.htm very helpful, along with this cookbook video https://www.youtube.com/watch?v=bSGzW4MnZ8E.
Jonathan
User | Count |
---|---|
2037 | |
1169 | |
770 | |
448 | |
333 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.