Hi,
I am trying to create policies based on AD-Users. So I connected our FGT to our DC and was able to retrieve the users I would like to use in our policies.
If I create a policy (LAN->WAN) -> Source: Username of the AD User ->> Destination WAN (all Services) the connection is not working.
So I assume there is some component missing. As far as I understood, we will have to install the FSSO Agent on Windows AD and create a connection on our FGT to this SSO Agent, to authenticate our logged in PC-Users to the FGT (=the FGT can check if the user is logged in correctly to AD).
Is this correct, or should the above mentioned, also work without any Clientsoftware in AD-Environment?
Thanks a lot!
Solved! Go to Solution.
Hello @menatwork ,
Yes, you should use FSSO to achieve this request.
There are two types of FSSO for AD, with an agent, and without an agent.
On the agentless model, you can use FortiGate as a polling server. Fortigate can poll your AD server and learn who logged in.
With an agent, you need to install a Fortinet Single Sign-on agent on your ad or other server. Agent poll your AD server consolidate all login data and send to FortiGate.
And also my preference is the agent model.
You can review these links about agent and agentless models.
Hello @menatwork ,
Yes, you should use FSSO to achieve this request.
There are two types of FSSO for AD, with an agent, and without an agent.
On the agentless model, you can use FortiGate as a polling server. Fortigate can poll your AD server and learn who logged in.
With an agent, you need to install a Fortinet Single Sign-on agent on your ad or other server. Agent poll your AD server consolidate all login data and send to FortiGate.
And also my preference is the agent model.
You can review these links about agent and agentless models.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.