Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cheetah111
New Contributor

Using sAMAccountName in Firewall Policies via Remote LDAP User Definitions with FSSO

Current Setup:
I have configured FSSO with FortiGate.
By default, when defining users in a firewall policy using FSSO, I have to select users via CN (Common Name) rather than sAMAccountName.
To resolve this, I created a User Definition on the FortiGate with the type Remote LDAP. This allows me to define the user in the firewall policy using the sAMAccountName.

 

Observations:
In my testing, this works well. When a user logs in/out of Windows, FSSO detects the event and sends the log events to the FortiGate.
Even if a user changes their IP while logged in, FSSO detects the new IP and updates the FortiGate.
Overall, the tests are successful.

 

Questions:
1. Because I cannot find any official documentation supporting this specific configuration. Are there any hidden risks?
2. Is this feasible for a production environment?
3. Can someone explain the mechanism and the difference between this and the standard configuration?

0 REPLIES 0
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors