Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Noxion
New Contributor

Fortigate FSSO with Microsoft RRAS VPN

Dear community,

 

We are planning to implement FortiGate FSSO in our organization. However, we have a Microsoft Routing and Remote Access VPN solution and I am wondering whether these would work together.

 

In other words; does RRAS log the required logon events on the domain controllers for FSSO to work?

 

I can't find any info on this online, Perhaps someone here has experience with such a setup?

 

Regards,

Noxion

____
Wake me up when winter is over...
____Wake me up when winter is over...
2 REPLIES 2
pminarik
Staff
Staff

The supported list of event IDs is documented ( https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Windows-event-IDs-used-by-FSSO-in... ), so my suggestion would be that you generate a couple of test logins to your VPN, and then check on your DCs if these events are being recorded at the time of the VPN login.

 

As an alternative, if you can set up RADIUS accounting in RRAS (I don't know), you could either feed the accounting packets to an FSSO Collector Agent, or FortiAuthenticator, to generate FSSO events out of them, or feed them directly to the FortiGate to generate RSSO sessions (warning: RSSO does not do any additional group lookups, it relies on the accounting packets already containing group membership info).

[ corrections always welcome ]
Noxion
New Contributor

Hello Pminarik,

Thanks for your reply. I tried what you suggested, and indeed Event 4776 is logged on one of the domain controllers. I will continue to configure FSSO to see whether it will work.

I’ll report my findings back here for future reference.

____
Wake me up when winter is over...
____Wake me up when winter is over...
Labels
Top Kudoed Authors