Our client is using Vasco devices with Fortigate, and after authentication to VPN device they want SSO towards their internal services – FTP, SMB, RDP, WWW, and I have difficulties designing such a scenario, as it is not clear how FortiNet Connection manager really implements functionality.
I have an issue understanding how VPN SSL web-mode works for:
a) HTTP internal services
b) FTP internal services
c) VNC connections
d) RDP connections
I have some questions, but i don‘t know right answers. In particular:
a) From documentation, it seems that they do not use port forwarding mode, right?
b) There is no agent, thus no additional IP interface is created, i.e. no IP address allocation from internal network space.
c) RDP uses native RDP windows client, then does it use FortiGate device as RDP proxy server? Is that the same with VNC?
d) How HTTP forwarding is working – does it uses some kind of encapculation (inside Java)?
e) SMB/CIFS/FTP – it uses connection manager’s client on fortigate, is that right
who knows the answers?
thanks for helping