Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

authentication with FGT100 2.80mr5

hello, we use a FGT 100 2.80 build 219 and the we have a problem with authentication. a user log on his pc, log on the fortigate to access the internet( valid for 25 min) after 5 minute he close his windows session and another user log on the pc and gain access to internet through the authentication of the fisrt user. how can we solve this problem? we can,t use a externeal server for authentication because the group that is authorize to access internet use also web filter
2 REPLIES 2
UkWizard
New Contributor

The authentication in the fortinet firewalls is a gimmick add-on, and not supposed to be a corporate grade solution. So it is not possible to get around this, as it basically allows this ip for the set amount of time. (imagine a terminal server environment, everyone would be coming from one ip address) You should really look at using a proxy server instead, and get that to auth. look for one that does NTLM authentication, as then the users do not have to type anything in at all, as its done transparently using windows username/password pair. I tested ' freeproxy' recently and was impressed that the NTLM worked on a free program, but couldnt see a way to restrict to a group. (would just allow all domain/local machine users). I can highly recommend the bluecoat appliance, but it is quite expensive.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UkWizard
New Contributor

Just found out, the free proxy software can do auth against users, you just have to type the usernames into a group for the rule. Will then use the transparent auth in the background against a server/workstation. Software is here; http://www.handcraftedsoftware.org/
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Labels
Top Kudoed Authors