Current Setup:
I have configured FSSO with FortiGate.
By default, when defining users in a firewall policy using FSSO, I have to select users via CN (Common Name) rather than sAMAccountName.
To resolve this, I created a User Definition on the FortiGate with the type Remote LDAP. This allows me to define the user in the firewall policy using the sAMAccountName.
Observations:
In my testing, this works well. When a user logs in/out of Windows, FSSO detects the event and sends the log events to the FortiGate.
Even if a user changes their IP while logged in, FSSO detects the new IP and updates the FortiGate.
Overall, the tests are successful.
Questions:
1. Because I cannot find any official documentation supporting this specific configuration. Are there any hidden risks?
2. Is this feasible for a production environment?
3. Can someone explain the mechanism and the difference between this and the standard configuration?
| User | Count |
|---|---|
| 2868 | |
| 1445 | |
| 831 | |
| 820 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.