Version: 7.4.0.0.427
Need help finding where to disable when a user is disabled in AD the host(s) that is registered to said user has all of its adapters disabled.
I'm not seeing Mappings to cause this action, hoping I can be pointed in the right direction.
Thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Sir,
Can you please explain more, you have disable user in active directory and you want to disable user in firewall ?
This is only regarding FortiNAC.
When a user is disabled in AD, once FortiNAC syncs with AD and sees that user is disabled it will:
1. Disable the User in the NAC
2. Disable adapters of any host that were registered to the host in the NAC.
I would like to disable this function.
FortiGate itself does not directly enable or disable network adapters on endpoints based on Active Directory user status. Instead, FortiGate manages network access and security policies, including user-based policies through FSSO.
Here is the log messages that FortiNAC is performing.
Is it required to do that?
A user account and a host are separate things, I mean when a user is disabled you can still connect from the same host with a different account.
Second thing, when your user is disabled at AD level, the user is not supposed to be able to authenticate on any host, even FNAC can't authenticate it with AD, so FNAC is supposed to keep him isolated, right?
This behavior is by default. There are two options to bypass this:
- Change the host "Registered To" attribute to another user before disabling the user in AD.
- On LDAP configuration in FNAC remove the "Disabled Attribute". This way FNAC will not read this attribute from the next LDAP synchronization and will not take any action for users that are disabled in AD:
More information can be found in the admin guide.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1669 | |
1082 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.