Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jongmun
New Contributor

SSO with EntraID

 Hi,

 

 I have Fortegate 100F with OS 7.4.x

 I configured SSO with EntraID successfully and login was working.

 

 I have a questions.

Q) Can I use more than one entra id group for separate vpn portal and policy.

 A user member of group A and assigned the portal A and apply policy A,

 and B user member of group B and assigned the portal B and apply policy B

 

And I have in trouble

T) User can login was successfully with Entra ID, and connected.

But SSL VPN client didn't receive internal routing table, only DMZ routing table was received.

It add routing table in manually 'route -Add xxx -mask...' then it can be communicated.

Anyone have solution like issue, please help me.

 

Thank You.

 

1 Solution
sjoshi
Staff
Staff

Hi,

 

Yes you can setup multiple portal and different policy for entra ID group using object ID

https://docs.fortinet.com/document/fortigate-public-cloud/7.6.0/azure-administration-guide/584456/co...

 

Regarding 2nd issue check the split routing setup

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi

View solution in original post

3 REPLIES 3
sjoshi
Staff
Staff

Hi,

 

Yes you can setup multiple portal and different policy for entra ID group using object ID

https://docs.fortinet.com/document/fortigate-public-cloud/7.6.0/azure-administration-guide/584456/co...

 

Regarding 2nd issue check the split routing setup

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
Jongmun
New Contributor

 

Thank you for your reply.

 

While I check as your advice, I found something wrong.

 

User A is member of EntraID GroupA and user A is logon OK then I remove membership in EntraID, now user A have no VPN permission and he shouldn't login.
But user A can logon and user A member of the others group, in VPN logon monitoring screen.

User A have no membership of the others group.

Do I more set EntraID or Fortigate?

Please help me..

 

Jongmun
New Contributor

Hello,

 

The issue has been solved.

 

casue:

The group member setting of fortigate was set to only azure as set in sso, and the group UID was not added, so authority was granted to all azure users.   :)

Now woking perfectly.

 

One more thing I found out is that, as you said, you can create multiple groups in entraid and use them, but it does not support more than one group. If a user is included in group A and group B, only one of the two is applied and the settings are granted, so in order to control the destination, you need to control it in the policy, and you should not use override in the vpn portal to limit the address.

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors