Hi Folks,
I would like to set up a Fortigate Firewall running 5.4.7 as an explicit proxy and have users authenticate by typing in their username and password. I want different A/D user groups to have different security profiles. So what I would like to do is just set up LDAP and use only LDAP authentication for the users. Can anyone tell me if this is possible? And if so which authentication method I should use in the proxy policy?
I could use FSSO but some devices are not on the domain, so I would rather just use LDAP credentials for the authentication. Any pointers appreciated.
Thanks, Moby.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Moby,
This is possible but you will find the web page that requests the credentials is not served over HTTPS. This means your users' credentials (including password) will be sent over the network in plain text. I consider that to be a massive short fall.
I found this article http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-WAN-opt-54/web_proxy.htm very helpful, along with this cookbook video https://www.youtube.com/watch?v=bSGzW4MnZ8E.
Jonathan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.