Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
appal10
New Contributor

Nested Groups in AD

Hi, we have configured in our company the integration between Active Directory (LDAP) and our Fortigate 60C (FortiOS 5.2.3) and we want to enable the nested detection for LDAP in FortiOS. The goal of this is to use a AD group which gives access to the VPN where we can put other groups inside which user receive that access too.

 

Actually we put other groups under the first one, and that users cannot access to the VPN, receiving a permission failure. If we put those users in the parent group, they receive the correct permission and they can use the VPN. Therefore, enabling the nested configuration with command "set search-type nested" would fix this issue? We are not using at this moment the SSO.

 

I have another question... if we want to rollback this change, how can we change it to the default behaviour? I have not found any information in the handbook.

 

Thank you very much

2 REPLIES 2
xsilver_FTNT
Staff
Staff

Hi,

maybe I'm old fashioned and keen to keep things simple stupid, but what about to use explicit single group for VPN allowed users and add all the users to that group as well ? Instead of multi-nested scenario where at the end might not be so clear which users are truly members.

 

And for rollback .. config backup ?

1. backup old config (backup-1)

2. commit changes

3. test changes ..

- results OK = keep config and make backup-2

- results NOK = restore backup-1 <= rollback

 

Best regards, Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

rwakelin
New Contributor

You have to select the "recursive" option in the ldap parameter.

You have to add search-type nested to the ldap definition from the command line.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors