Greetings!
We use FSSO for authentication and identity-based policies. We have a catch-all policy in place which provides minimal access to the Web for users/machines not authenticated via FSSO.
I'd like our catch-all policy to instead prompt for web-based authentication against LDAP instead so that the proper policies can be applied to the user.
Can this be done?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
yes, it can be done.
Edit: I guess I could tell you how.
I assume you're on 5.2, but even if you're still riding the 5.0 train it's very similar.
You'll need to create an LDAP connection and then create an LDAP group. Once this is done you create your policy for authentication(which it sounds like you already have).
in 5.0 you would create a sub-policy underneath the policy with FSSO authentication. In that policy, instead of using an FSSO group, you would in turn use the LDAP group you created.
in 5.2 you would just add the LDAP group to the policy that each associated FSSO group is in. This way it will fall to the captive portal in case FSSO dinks up on you.
Also, make sure the sequential order is proper and you should be golden.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.