Hi everyone!
I'm deciding whether or not to implement FSSO to our existing environment but aren't quite sure why we would do that? What are the pro's and cons and also what does it add to an environment?
Thanks in advance
Lennert
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Pro works great
Con, does not satisfy any non MS-domain device. I don't know how you can monitor multiple Domains and multiple FSSO agent in a multi-domain environment
Ken Felix
PCNSE
NSE
StrongSwan
Hi,
multi-domain is more complex to install and configure properly, but it is supported too.
It depends if it's a domain forest or distinct domains with trusts only.
I can't be really comprehensive here (it would be very long writing), so if you have any concerns regarding multi-domain FSSO, let me know your domain setup and I will try to respond with some notes.
Non-domain devices+domain users can be authenticated by other means (portal, other device) and imported into FSSO ie with Radius Accounting (which can be processed on FSSO CA).
If you have more complex non-domain environment, you can consider to use FAC with number of techniques of logging in user and push it via FSSO into Fortigate. FAC is very strong at this (I wouldn't use it for FSSO itself, though -- requires licensing + my personal preference is standalone FSSO CA).
Regards,
Fishbone)(
smithproxy hacker - www.smithproxy.org
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1711 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.