Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nbcuser
New Contributor

Optional authentication for extra web access

Hi All,

 

I am a P-12 school and have a 300C running 5.2.3.  We have a mix of PCs, Macs and iPads.  While we have a Windows AD Domain not all of our devices are bound or login to the domain.  We don't have access to our WLC to do any Radius authentication.

 

I'd like to setup the ability for staff to optionally authenticate with the Fortigate to gain extra web access.  This would allow them to access sites that are deemed inappropriate for the students.  I don't want to force the staff to have to authenticate all the time, and I don't want all our students to have to authenticate either.

 

I am quite new to the Fortigate so am wondering how others would go about achieving this?

 

Thanks in advance,

Chris.

1 Solution
emnoc
Esteemed Contributor III

I had that same issue but here's what we did. In our approach we worked with a pubicschool who had the same issues

 

   > a mix of PCs/MACs/

   > FSSO was out of the question

   > principal, police, resource officers,etc... got tired of being denied to just about anything nasty

   > etc.....

 

So we crafted a sslvpn group for faculty/staff/contractors/etc...

Allow them SSLVPN from  the local-lan or wifi,  with a security that was non or less restrictive than the students. The staff only needed to install a forticlient,  and life was full of gold at the end of the rainbow so to speak.

 

FWIW: The SSLVPN groups had full-to-unrestricted access from WEB ssh /telnet , etc....based on that group need,  and you SNAT the sslvpn ipv4-pool with the correct policies.

 

 

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
2 REPLIES 2
emnoc
Esteemed Contributor III

I had that same issue but here's what we did. In our approach we worked with a pubicschool who had the same issues

 

   > a mix of PCs/MACs/

   > FSSO was out of the question

   > principal, police, resource officers,etc... got tired of being denied to just about anything nasty

   > etc.....

 

So we crafted a sslvpn group for faculty/staff/contractors/etc...

Allow them SSLVPN from  the local-lan or wifi,  with a security that was non or less restrictive than the students. The staff only needed to install a forticlient,  and life was full of gold at the end of the rainbow so to speak.

 

FWIW: The SSLVPN groups had full-to-unrestricted access from WEB ssh /telnet , etc....based on that group need,  and you SNAT the sslvpn ipv4-pool with the correct policies.

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
nbcuser
New Contributor

Thanks emnoc,

 

that's an interesting suggestion - one that I hadn't considered - and I shall definitely investigate it further.

Cheers,

Chris.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors