Hi All,
I am a P-12 school and have a 300C running 5.2.3. We have a mix of PCs, Macs and iPads. While we have a Windows AD Domain not all of our devices are bound or login to the domain. We don't have access to our WLC to do any Radius authentication.
I'd like to setup the ability for staff to optionally authenticate with the Fortigate to gain extra web access. This would allow them to access sites that are deemed inappropriate for the students. I don't want to force the staff to have to authenticate all the time, and I don't want all our students to have to authenticate either.
I am quite new to the Fortigate so am wondering how others would go about achieving this?
Thanks in advance,
Chris.
Solved! Go to Solution.
I had that same issue but here's what we did. In our approach we worked with a pubicschool who had the same issues
> a mix of PCs/MACs/
> FSSO was out of the question
> principal, police, resource officers,etc... got tired of being denied to just about anything nasty
> etc.....
So we crafted a sslvpn group for faculty/staff/contractors/etc...
Allow them SSLVPN from the local-lan or wifi, with a security that was non or less restrictive than the students. The staff only needed to install a forticlient, and life was full of gold at the end of the rainbow so to speak.
FWIW: The SSLVPN groups had full-to-unrestricted access from WEB ssh /telnet , etc....based on that group need, and you SNAT the sslvpn ipv4-pool with the correct policies.
PCNSE
NSE
StrongSwan
I had that same issue but here's what we did. In our approach we worked with a pubicschool who had the same issues
> a mix of PCs/MACs/
> FSSO was out of the question
> principal, police, resource officers,etc... got tired of being denied to just about anything nasty
> etc.....
So we crafted a sslvpn group for faculty/staff/contractors/etc...
Allow them SSLVPN from the local-lan or wifi, with a security that was non or less restrictive than the students. The staff only needed to install a forticlient, and life was full of gold at the end of the rainbow so to speak.
FWIW: The SSLVPN groups had full-to-unrestricted access from WEB ssh /telnet , etc....based on that group need, and you SNAT the sslvpn ipv4-pool with the correct policies.
PCNSE
NSE
StrongSwan
Thanks emnoc,
that's an interesting suggestion - one that I hadn't considered - and I shall definitely investigate it further.
Cheers,
Chris.
User | Count |
---|---|
2061 | |
1175 | |
770 | |
448 | |
343 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.