Hi, we have configured in our company the integration between Active Directory (LDAP) and our Fortigate 60C (FortiOS 5.2.3) and we want to enable the nested detection for LDAP in FortiOS. The goal of this is to use a AD group which gives access to the VPN where we can put other groups inside which user receive that access too.
Actually we put other groups under the first one, and that users cannot access to the VPN, receiving a permission failure. If we put those users in the parent group, they receive the correct permission and they can use the VPN. Therefore, enabling the nested configuration with command "set search-type nested" would fix this issue? We are not using at this moment the SSO.
I have another question... if we want to rollback this change, how can we change it to the default behaviour? I have not found any information in the handbook.
Thank you very much
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
maybe I'm old fashioned and keen to keep things simple stupid, but what about to use explicit single group for VPN allowed users and add all the users to that group as well ? Instead of multi-nested scenario where at the end might not be so clear which users are truly members.
And for rollback .. config backup ?
1. backup old config (backup-1)
2. commit changes
3. test changes ..
- results OK = keep config and make backup-2
- results NOK = restore backup-1 <= rollback
Best regards, Tomas
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
You have to select the "recursive" option in the ldap parameter.
You have to add search-type nested to the ldap definition from the command line.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.