Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
muhammadsaad
Contributor

LDAP user group based policy not working on fortigate

Hello,

We’re experiencing an issue where firewall policies that use LDAP-based user groups are not functioning as expected. Our goal is to restrict access to certain websites for specific LDAP users.

Here’s what we’ve done so far:

  • Configured an LDAP server.

  • Created a user group, fetched users from LDAP, and applied the group to the firewall policy.

  • Additionally, we set up an external connector for the Active Directory Server, fetched the required users through it, and used the same FSSO user group in the firewall policy.

Unfortunately, the configuration isn’t working as intended.

Could someone please assist us in troubleshooting this issue and provide guidance on how to resolve it?

5 REPLIES 5
Shyy
New Contributor

First of all if you are able to fetch the groups thats a good start.
Have you added in the firewall policy the network subnet in addition to the user group?
What did you exactly configure in the firewall policy that is not working exactly?

muhammadsaad

Hi,

Thanks for your reply.

I have created a firewall policy and defined the following source (user group and all).

Also in the source when we assigned only IP of the user, then the policy worked perfectly.

 

When we try to test with user group policy, it doesn't work.

 

Shyy

User group shouldn't be any different from a normal user, as long as you've fetch all the information correctly, you sure you've put the relevant subnet pool in the policy as well with the group?

muhammadsaad
Contributor

We have created a user group and add the remote groups fetched from the AD on it.

After that, the firewall policy having below main details:
1. Source (user group and 'all')

2. Destination (FQDN for youtube i.e. *.youtube.com)
3. Action Deny

4. Incoming and outgoing interfaces defined accordingly.

Shyy

If that's the case you should do a debug and make sure that the traffic is going over the right firewall policy 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors