Dear community,
We are planning to implement FortiGate FSSO in our organization. However, we have a Microsoft Routing and Remote Access VPN solution and I am wondering whether these would work together.
In other words; does RRAS log the required logon events on the domain controllers for FSSO to work?
I can't find any info on this online, Perhaps someone here has experience with such a setup?
Regards,
Noxion
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The supported list of event IDs is documented ( https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Windows-event-IDs-used-by-FSSO-in... ), so my suggestion would be that you generate a couple of test logins to your VPN, and then check on your DCs if these events are being recorded at the time of the VPN login.
As an alternative, if you can set up RADIUS accounting in RRAS (I don't know), you could either feed the accounting packets to an FSSO Collector Agent, or FortiAuthenticator, to generate FSSO events out of them, or feed them directly to the FortiGate to generate RSSO sessions (warning: RSSO does not do any additional group lookups, it relies on the accounting packets already containing group membership info).
Hello Pminarik,
Thanks for your reply. I tried what you suggested, and indeed Event 4776 is logged on one of the domain controllers. I will continue to configure FSSO to see whether it will work.
I’ll report my findings back here for future reference.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.