Hello,
I have set up a firewall policy to test our FSSO functionality. I have noticed that when the FSSO group corresponds to a user DN it works fine, however, if it corresponds to a Global Security group, it does not work.
Below is the firewall policy:
show firewall policy ***
config firewall policy
edit ***
set name "TestFSSO"
set uuid f44e2db6-3fe8-51f0-****-6d00*****3be
set srcintf "lan"
set dstintf "wan1"
set action accept
set srcaddr "all"
set dstaddr "all"
set schedule "always"
set service "ALL"
set utm-status enable
set inspection-mode proxy
set profile-protocol-options "custom-default"
set ssl-ssh-profile "certificate-inspection"
set av-profile "default"
set webfilter-profile "Default"
set dnsfilter-profile "default"
set ips-sensor "Default"
set application-list "Default"
set logtraffic all
set nat enable
set ippool enable
set poolname "Web Browsing Users"
set groups "test fsso"
next
end
What I mean is that if "test fsso" contains a user DN, the policy works as expected. If "test fsso" contains a GS DN, it does not. The GS I'm pointing out to has the same user member.
Any advice?
Thank you
Solved! Go to Solution.
After talking to Fortinet Support Team, below solution looks to work for us.
https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Windows-event-IDs-used-by-FSSO-in...
Hi Danyal
Is the group nested?
Can you try the group that directly owns the user?
Created on 06-05-2025 10:09 AM Edited on 06-05-2025 10:10 AM
Hi Aek,
As I mentioned, it works when the user group owns the user directly. However, I would like to get it work with active directory Global Security.
After talking to Fortinet Support Team, below solution looks to work for us.
https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Windows-event-IDs-used-by-FSSO-in...
User | Count |
---|---|
2431 | |
1304 | |
778 | |
565 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.