Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Pauwlo
New Contributor

"Access Denied" on some folder using the SMB Widget on the SSL VPN portal.

Hi,

 

I write a thread because I did not found my issue on the forum or on the Internet.

I set up a SSL VPN portal on my Fortigate and added a SMB/CIFS bookmark which link to my network share.

When I click on this bookmark I can log in and access my share but on some specific folders I have an "Access Denied" message.

I can correctly browse theses folder if I use the native windows file browser.

The only think I saw is that the root folder has read access for the "Everyone" group and the folders I have problems with have more specifics rights such as "Read access for the "Company_Members" group".

 

Did you already meet this issue or do you have an idea to start troubleshooting this issue ?

 

Regards, Pauwlo.

4 REPLIES 4
mjcrevier
New Contributor III

How are you authenticating users that login to the SSL portal? LDAP/RADIUS/Local?

Pauwlo

mjcrevier wrote:

How are you authenticating users that login to the SSL portal? LDAP/RADIUS/Local?

Hi Mjcrevier,

 

I am authenticating my users with LDAP (on AD). I tried to enable the SSO on the portal, I was not asked for my credentials while connecting to the share but I get the same issue.

 

Regards, Pauwlo.

fjansson
New Contributor II

Hi!

 

Not sure if you managed to get this working but I found another "solution" on the forum, regarding the 'Access Denied' bit. 

 

Apparently if you fill in domain\username in the username/password boxes you are able to connect to the shares. No access denied or anything. 

 

So for example:

"domain.local\username" + password works, but only filling in the username doesn't. 

 

This was taken from the following thread from 2012, so it seems the issue is still present:

https://forum.fortinet.com/tm.aspx?m=92268&tree=true

 

== Update ==

Below settings were entered on a FortiGate v5.2.4,build688

 

To be able to do this without having to fill in domain\username, edit the following settings:

 

#config vpn ssl settings  set dns-suffix domain.local

 

Then, navigate to the relevant bookmark and select SSO: auto

 

Also, make sure the file share you are entering is not a DFS share, as this will not work (at least when I tried it).

 

 

Kind regards, Frida

fjansson
New Contributor II

An update on this:

 

I managed to get this working without having to manually fill in domain\username.

 

This was done on a Fortigate v5.2.4,build688:

 

#config vpn ssl settings  set dns-suffix domain.local

 

Also, set sso -> auto on the relevant bookmark.

 

Make sure that you are using a non DFS fileshare as well, I didn't get it to work with DFS at least.

 

Kind Regards, Frida

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors