Hi All,
Testing a new rule restricted to a single user to test LDAP connectivity and future lockdown. Currently using a Fortigate 200E on software version 6.0.3.
I have configured LDAP connectivity and created a user group containing the single user through FSSO. Rather than using a specific group I have selected the user in the all staff list for the user group.
I have created a standard rule with a source of the user and all IPs, destination of Yahoo Web for testing, PAT to internet with AV, Web and SSL inspections.
This rule is placed at the top of the rule stack to be first hit. When testing, I can access the Yahoo site but see no hit on this specific rule so the master rule below is being hit.
Have I missed anything here?
Regards
Adrian
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi - do you see your username on the FSSO list? - how did you specify destination (Yahoo), IP, ISDB?
Enable logging all sessions and compare the log with the policy (authentication, destination, etc.)
When running the command in CLI I do not see my entry. Only one user in another FSSO group we have for All Users.
Specified Yahoo through use of Internet Service Yahoo Web.
Think I found the problem. When running debug for server-status I get a local fsso error connection refused. Since we have an agent on the DC I understand this isn't needed so I need to remove it from 'config user fsso-polling' ensure my fsso 'config user adgrp' records are paired to right Collector.
Question is, will this impact any of the policy when I apply - understand that it's not working now?
Strange thing is we have a FSSO group for all users and whilst I am awaiting the person who manages the LDAP server to tell me who is a member of that group, I only see one person listed when over 200 would be expected but that is another issue.
Thanks in advance for help.
Regards
Adrian
Yes, when you have agent on DC you don't need fsso-polling configuration. It shouldn't impact policy configuration but every time when you change config do backup, it's a good pratice
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.