Hello,
I've got an issue with a user ldap authentication for about 10 minutes during which IP was recognized as guest user in FSSO_Guest_Users group. After user successfully turned in authentication guest disappeared. I've been reading the following doc http://kb.fortinet.com/kb/documentLink.do?externalID=FD35363 but it is not still evident to me the way guest user and related FSSO_Guest_Users works with no matching identity policy rules for guest or FSSO_Guest_Users group.
Thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
basically said, if FSSO Guest Group is used (usually as the last group) in FortiOS 5.0 or 4.3 Identity-based policy using FSSO.
Then if users' traffic match that policy but user is not found/matching any record from FSSO user list (diagnose debug authd fsso list) , then user pass through FSSO Guest Group and his traffic is marked as from FSSO guest.
Kind regards, Tomas
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.