- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Info about user identification
Hello team,
I have the users of a branch office that to go out on the Internet they do this circuit
VLAN_Client --> FGT-200F --> MPLS Circuit --> FGT-400F
On the 400F firewall various browsing profiles are configured which according to the AD group they belong to are assigned a Lite,Full or Basic browsing profile.
Now looking at the logs on the 200F side (defult gateway VLAN_Client) I see correctly the IP address with the domain username
While looking at the logs from the 400F side I see the local ip, the natted ip but not the domain user
and as a result it never matches the policy for the browsing profile since there is an ad group as the source.
How do I see the ip-AD user mapping on the 400F as well? Any suggestions?
Thanks
BR
Solved! Go to Solution.
- Labels:
-
FortiGate
Created on ‎02-19-2024 10:34 AM Edited on ‎02-20-2024 01:49 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Luca
You man not need setup FSSO on both. If you just need on one FW, doing user filtering on both FWs may be waste of resources. It depends on your design.
Regarding FSSO setup, take time to read it well before setup because it can be a bit complicated.
We can then guide you with pleasure.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Luca
If I'm not wrong you are not using FSSO on 200F neither on 400F.
In that case the user id you see on 200F is collected from client's DHCP request or something similar, and you can't do any filtering based on that.
To be able to filter based on AD group you need setup FSSO.
https://docs.fortinet.com/document/fortigate/7.2.7/administration-guide/450337
Or if you need something simpler you can also use active portal if it is suitable for your case.
https://docs.fortinet.com/document/fortigate/7.2.7/administration-guide/934626
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @AEK ,
exactly, i'm not using FSSO. So, if i configure FSSO for both Fortigte (200F e 400F) can i filter by user id? I must install FSSO agent on Windows DCs and configure connector on both firewalls?
Thanks for the support Aek.
BR
Created on ‎02-19-2024 10:34 AM Edited on ‎02-20-2024 01:49 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Luca
You man not need setup FSSO on both. If you just need on one FW, doing user filtering on both FWs may be waste of resources. It depends on your design.
Regarding FSSO setup, take time to read it well before setup because it can be a bit complicated.
We can then guide you with pleasure.
