Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

LDAP SSO with proxy authentication

Hello Fellas,

 

Got a chance to post one of my client request. Explicit Proxy with Authentication.

Based on the attached screenshot is this feasible? If yes why my login account not working?

 

Note: AD/LDAP Server is running on Windows 2003 R2.

 

Tried the ff logins methods but no success;

username/domain.com

password

**********

domain/username

password

********

username@domain.com

password

Pls see screenhots 1-4 for reference.

 

Any feed back is much appreciated. Thank you in advance

 

 

 

Fortigate Newbie

Fortigate Newbie
18 REPLIES 18
Fullmoon
Contributor III

Step 2

Fortigate Newbie

Fortigate Newbie
Fullmoon

Step 3

Fortigate Newbie

Fortigate Newbie
Fullmoon

step 4

Fortigate Newbie

Fortigate Newbie
Fullmoon

Any help? :)

Fortigate Newbie

Fortigate Newbie
HA
Contributor

Hello,

 

Replace the 'CN' value in the common name identifier with 'sAMAccountName'.

 

See http://www.firedaemon.com/blog/fortinet-fortigate-300c-active-directory-integration

 

Regards,

 

HA

Fullmoon
Contributor III

Hi HA,

 

thanks for paying attention to my post. Yes that's my initial troubleshooting, changed common name identifier from CN to sAMAccountName and vice versa.

what would be the format of the credentials I am going to use in the authentication page?

Ex. username@domain.com or domain.com/username

 

Rest assured the username being inputted was correct.

 

 

Fortigate Newbie

Fortigate Newbie
HA
Contributor

Hello,

 

Why don't you use NTLM ??

It will allow to do SSO (without entering the credential in the popup)...

 

Regards,

 

Hedi

 

Fullmoon
Contributor III

sounds new to me HA, I would deeply appreciate if you could send some procedure or screenshots to have a full picture...thank you so much in advance

Fortigate Newbie

Fortigate Newbie
HA
Contributor

Hello,

 

In the screnshot Step 4 that you post, change the following value:

1. Uncheck 'Enabled IP Based authentication'

2. Default Authentication Method: Choose NTLM.

 

Regards,

 

HA

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors