Hi,
I have addedd my AD LDAP it have status connected, now I would like to create firewall policy with source as AD users groups, but I have not here any group from AD listed, how could I troubleshoot this?
Hello Tutek,
Have you added the AD groups in a user group(s)? The user groups should then be visible in firewall policies.
Best Regards,
Alivo
livo
Hi, I created local groups and assign this group to remote NPS server the same name group.
You can't mix local and LDAP users in the same group. Create new user group and put there as member the LDAP object you created, then use this group in src in rules.
as you can see regarding this KB:
is possible to choose AD groups in firewall policy.
When I create firewall policy in users then select entry-->User here I don't have listed my AD groups, why?
Hello Tutek, The doc is about fsso. Not LDAP. Although you may see it as LDAP groups which in fact these are,
they belong to different table in FortiGate > adgrp. This is used for passive authentication > Fortinet Single Sign On.
Since you added LDAP groups, as you wrote in your initial post, you have chosen active authentication > meaning users will be prompted for their credentials.
What is your goal exactly?
Best Regards,
Alivo
livo
I would have ability choose my pooled AD group directly in firewall policy, as shown here
I have configured agentleess pooling to my domain controller, and checked two AD group to pool, but when create firewall policy when i click source then Select Entry "User", but I don't see here any of my AD groups.
Hello Tutek,
1. which firmware are you using?
2. What is the source interface in the policy
3. what is the output of: sh us adgrp
Thank you.
Best Regards,
Alivo
livo
1.v6.4.5 build5653 (GA)
2.I want to restrict Internet access only to pooled from AD "Domain users", so source interface is my LAN.
3.
FGT # sh us adgrp config user adgrp end
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.