So....
Two FSSO groups General Users and Social Medial. I have two identical Firewall Policies except that one has a filter profile that references the General users and the General Filtering Policy. The other references the Social Media group and policy....
So...The way it works is that once it gets a User Group match then it processes that policy. It's a firewall and that's the way it works.... So, basically the policies need to be arranged from least restrictive to most restrictive. You can only really support a single match.
The only question I have is I thought there was a concept called Fall-through rules or something like that introduced in 5.2 which could support multiple group matches. Is that something that does exist and/or my expectations of what it actually does are incorrect?
I really never seen fall-thru but have you ran diag debug flow and follow the policy execution & selection
PCNSE
NSE
StrongSwan
mwkirk wrote:Did you ever manage to find out what happens with a user with multiple groups? I'm in the same boat.So....
Two FSSO groups General Users and Social Medial. I have two identical Firewall Policies except that one has a filter profile that references the General users and the General Filtering Policy. The other references the Social Media group and policy....
So...The way it works is that once it gets a User Group match then it processes that policy. It's a firewall and that's the way it works.... So, basically the policies need to be arranged from least restrictive to most restrictive. You can only really support a single match.
The only question I have is I thought there was a concept called Fall-through rules or something like that introduced in 5.2 which could support multiple group matches. Is that something that does exist and/or my expectations of what it actually does are incorrect?
Mostly adding these notes for others that may come across this question. These two Technical Notes/Tips provide information on fall through behavior for unauthenticated users.
User | Count |
---|---|
2116 | |
1187 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.