Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ddiez
New Contributor III

restricted (filtered) user logins to web targets via FortiPAM

Hi there,

 

how can I do the following to increase the security in using a PAM solution?

Given is a web launcher target that is only accessable via FPA - so far, this is good. But I want to assure that the login at the target is only made possible via FPA proxy connection with specific credentials.

Actually I can use the FPA web filler via browser addon on the target in the login mask - but (now that the connection to the target is possible due to the proxied way started from FortiPAM) I couls also enter any other credentials (as the first login attempt as well as after logging off after using the FPA credential way) ...

So I think there is a gap because herewith it is not possible to assure that no other credentials will be tried out or any full superadmin / root access can be made via this connection.

I searched for any options and tested with template modifications (web filler attributes) but did not get any successfull behaviour for this. Hoping that this is even possible in FortiPAM.

Any ideas or hints for me?

KuC
KuC
4 REPLIES 4
Jean-Philippe_P
Moderator
Moderator

Hello ddiez, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Regards,
Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Regards,
Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello again ddiez,

 

I found this solution. Can you tell us if it helps, please?

 

To increase security when using FortiPAM for accessing a web launcher target, you can configure the web proxy feature to ensure that only specific credentials are used for login. Here’s how you can achieve this:

  1. Enable the Web Proxy Feature: Ensure that the web proxy feature is enabled in FortiPAM. This feature allows FortiPAM to dynamically operate on the web browser tab's PAC rule to proxy traffic based on the configured domain.

  2. Create a Secret Target with Web Proxy: Define a secret target in FortiPAM that specifies the web launcher target. This configuration will ensure that the connection to the target is only possible through the FortiPAM proxy.

  3. Create a Secret with Web Proxy: Create a secret in FortiPAM that includes the specific credentials you want to use for the web launcher target. This secret will be used by the web proxy to authenticate the connection.

  4. Restrict Access to Other Credentials: Ensure that users do not have access to other credentials that could be used to log in to the target. This can be managed through FortiPAM’s access control policies.

  5. Monitor and Audit Access: Regularly monitor and audit access logs in FortiPAM to ensure that only authorized credentials are being used to access the web launcher target.

By following these steps, you can enhance security by ensuring that only the specified credentials are used for logging into the web launcher target through FortiPAM. If you need further assistance, consider consulting the FortiPAM Administration Guide or reaching out to Fortinet support.

Regards,
Jean-Philippe - Fortinet Community Team
ddiez

Hi Jean-Philippe,

 

thanks for your reply. I know about this features you mentioned, and all of this points are configured and used. But this is not the intention of my question: to enable a "full access tunnel using the web launcher towards the target without any user input possibilities in the browser - like the launch of a secret using PuTTY, for example, in this case the launcher is stareted "as it is" without any possibility to change the username / password that is used in this launcher session direct from FortiPAM.

 

Regards,

Daniel

KuC
KuC
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors