Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DarwinPH
New Contributor

Issue with User Identity Policy and Windows 8

Greetings to ALL! We setup a Fortigate 300C with User Identity Policy so that users will have to login first thru a LOGIN PAGE before being able to connect to the internet. We encountered a problem when some of our ' VIP users' bought new laptops with Windows 8 OS. They all login to their laptops using Microsoft Accounts and not local accounts. They wont be able to login to their laptops since internet connection wont be ' engaged' until they authenticate on the Fortigate LOGIN Page using a browser. In turn, they wont be able to open a browser since they cannot login to their laptops. Thanks in advance for your insights guys! Blessings!
4 REPLIES 4
Jeff_FTNT
Staff
Staff

You may try to add a policy on top to permit " Source Device Type=windows8" to reach " Microfogt Account login website" . So only Windows8 PC can reach " Microfogt Account login website" firstly, then if he access other website, it will go to LOGIN PAGE to authenticate again.
DarwinPH

Thank you for the suggestion! I will surely give that one a go. And update this thread after. But first i have to find out to what ' site / link / ip' Microsoft use for the account login. Anybody who has an idea what that might be? Thanks in advance! Blessings!
Jeff_FTNT
Staff
Staff

You may try to set up " FQDN" type address like: config firewall address edit " account.live.com" set type fqdn set fqdn " account.live.com" next end Add this address as destination on your policy, FGT to resolve its IP. # dia test application dnsproxy 6 vfid=1 name=account.live.com: timer running, min_ttl=297:290, cache_ttl=0 , slot=-1, num=1 64.4.16.215 (ttl=297:296:296)
DarwinPH

Appreciate it Jeff! Will give it a try. Thanks!
Labels
Top Kudoed Authors