Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SGalbincea
New Contributor

Predefined RDP Bookmark with Credentials Passthrough (i.e. Single Sign-On)

I am coming from using SonicWALL SRA appliances and am hoping to create a similar experience on the Fortigate with regard to logging into RDP bookmarks. Specifically, I would like to pass through the SSL-VPN user credentials (already LDAP) to an RDP bookmark that I have defined for all portal users. Is there a variable or something that I could use to define the username and password in the bookmark settings? Is there another way to accomplish this? Any help appreciated, thanks.

STEVE GALBINCEA   |   SENIOR NETWORK ENGINEER

LEADERHOUSTON VMWARE USERS GROUP

VCP5-DCV, VSP, VTSP, VMSP, VMTSP, NIOP BEMA Information Technologies

STEVE GALBINCEA | SENIOR NETWORK ENGINEER LEADER – HOUSTON VMWARE USERS GROUP VCP5-DCV, VSP, VTSP, VMSP, VMTSP, NIOP BEMA Information Technologies
4 REPLIES 4
SGalbincea
New Contributor

Bringing this back up for any and all feedback - we have many clients who desire this functionality.

STEVE GALBINCEA   |   SENIOR NETWORK ENGINEER

LEADERHOUSTON VMWARE USERS GROUP

VCP5-DCV, VSP, VTSP, VMSP, VMTSP, NIOP BEMA Information Technologies

STEVE GALBINCEA | SENIOR NETWORK ENGINEER LEADER – HOUSTON VMWARE USERS GROUP VCP5-DCV, VSP, VTSP, VMSP, VMTSP, NIOP BEMA Information Technologies
firestarter4711

Hello SGalbincea

 

yes of course that's possible.

 

What you'll have to do is to define a LDAP-Server connection using the UPN ('userPrincipalName') as a Common Name Identifier. Then you can add your Activedirectory global security group containing the users to the local fortigate group you are using in your portal definition.

 

After that you can login via upn and password, create a RDP-Bookmark with "Use SSL-VPN Credentials" enabled and there you go.

 

Currently - using FortiOS 5.6.2 i only discovered that this is only working with predefined bookmarks - either global or personal. It seems that it does not work correctly when I use the "Quick Connection" Feature, but you wrote you'll like to define the bookmarks anyway.

 

Another drawback - at least for my workmates - is that it doesn't work when you use 'sAMAccountName' as the Common Name Identifier. They'd been used to login with the username only instead of the userPrincipalName from now on.

Kenundrum

can you provide a snippet of what that looks like in CLI? I'm looking to do the same thing, but can't get it to work with RDP connections.

CISSP, NSE4

 

CISSP, NSE4
firestarter4711

hi,

 

yes i'll try to make a quick cli snippet from my configurations - when i'm done with my appointments today.

Labels
Top Kudoed Authors