Hello,
I have forti 3600c which i connect to my AD, and a i am trying to configure user rule.
See details:
My 3600c version: Version: FortiGate-3600C v5.0,build7746,150114 (GA)
My fortigate can see AD and works fine with him ( i can sse the users)
To configure user policy i configured:
[ol]My goal is to block user "testf" and only him, to do so i configured policy which src/dst ip is "any",
In the sub policy i took group"FSSO-Blocked-Users" which user "testf" is member, dst address are "all" and the action is Deny
And i have default deny sub-policy, i all so marked the "skip this policy for unauthenticated user"
When i unmarked "skip this policy for unauthenticated user" i lost internet connectivity for all users.
When i marked "skip this policy for unauthenticated user" my private user worked but also "testf" worked and didn't blocked.
I don't no what i am missing ????
See cli configuratin:
config firewall policy edit 112 set srcintf "any" set dstintf "any" set srcaddr "all" set action accept set status disable set fsso enable set fall-through-unauthenticated enable set global-label "Test" set replacemsg-override-group "auth-policy-112" set identity-based enable config identity-based-policy edit 2 set schedule "always" set logtraffic all set groups "FSSO-Blocked-Users" set dstaddr "all" set service "ALL" set action deny next end next
Regards
Rafi
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
I success with this it work fine all the time, but there is some 'bug' i think.
I checked the connection with ping to 8.8.8.8 and this is the status:
- if i set the policy to deny and then login everything work as expected (no ping and no internet)
- If i changed from deny to allow while im login the ping and internet start to work as expected, but when i chenged it back to 'deny' ping continue to work but no internet access.
But i have new problem, after i login the fortigate remember my ip address and even if i login with different user he still block me (because the ip is the same).
Does anyone have an idea ?
Rgards
Rafi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.