Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
echo
Contributor II

How to authenticate VPN users against AD + security group?

Hello! I have set up VPN-s against FortiGate units, both IPSEC and SSL, both FortiClient and Shrew (Shrew IPSEC only), but there is one thing that I haven' t managed yet: how to authenticate users based on their AD security group membership (edit:) with Radius. So far users can authenticate if their Dial-In properties is set to " Allow access" . In this case group membership is discarded altogether. If there is default " Control access through NPS policy" , then users won' t authenticate. But I have set up NPS policy for checking group membership and setting to do that for NAS-Port type VPN. Are there any " secret" configuration elements in NPS/IAS side like there were for Juniper VPN where I had to set vendor code 3228 for authentication and things like that?
2 REPLIES 2
Dipen
New Contributor III

For SSL-VPN you can Integrate with AD using LDAP Authentication rather than radius. SSL-VPN in Fortigate works seamlessly with LDAP AD Integration :)

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
echo
Contributor II

Well, yes, I really abandoned Radius after searching for a while and switched to LDAP which works.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors