Hi there,
how can I do the following to increase the security in using a PAM solution?
Given is a web launcher target that is only accessable via FPA - so far, this is good. But I want to assure that the login at the target is only made possible via FPA proxy connection with specific credentials.
Actually I can use the FPA web filler via browser addon on the target in the login mask - but (now that the connection to the target is possible due to the proxied way started from FortiPAM) I couls also enter any other credentials (as the first login attempt as well as after logging off after using the FPA credential way) ...
So I think there is a gap because herewith it is not possible to assure that no other credentials will be tried out or any full superadmin / root access can be made via this connection.
I searched for any options and tested with template modifications (web filler attributes) but did not get any successfull behaviour for this. Hoping that this is even possible in FortiPAM.
Any ideas or hints for me?
Hello ddiez,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Hello again ddiez,
I found this solution. Can you tell us if it helps, please?
To increase security when using FortiPAM for accessing a web launcher target, you can configure the web proxy feature to ensure that only specific credentials are used for login. Here’s how you can achieve this:
Enable the Web Proxy Feature: Ensure that the web proxy feature is enabled in FortiPAM. This feature allows FortiPAM to dynamically operate on the web browser tab's PAC rule to proxy traffic based on the configured domain.
Create a Secret Target with Web Proxy: Define a secret target in FortiPAM that specifies the web launcher target. This configuration will ensure that the connection to the target is only possible through the FortiPAM proxy.
Create a Secret with Web Proxy: Create a secret in FortiPAM that includes the specific credentials you want to use for the web launcher target. This secret will be used by the web proxy to authenticate the connection.
Restrict Access to Other Credentials: Ensure that users do not have access to other credentials that could be used to log in to the target. This can be managed through FortiPAM’s access control policies.
Monitor and Audit Access: Regularly monitor and audit access logs in FortiPAM to ensure that only authorized credentials are being used to access the web launcher target.
By following these steps, you can enhance security by ensuring that only the specified credentials are used for logging into the web launcher target through FortiPAM. If you need further assistance, consider consulting the FortiPAM Administration Guide or reaching out to Fortinet support.
Hi Jean-Philippe,
thanks for your reply. I know about this features you mentioned, and all of this points are configured and used. But this is not the intention of my question: to enable a "full access tunnel using the web launcher towards the target without any user input possibilities in the browser - like the launch of a secret using PuTTY, for example, in this case the launcher is stareted "as it is" without any possibility to change the username / password that is used in this launcher session direct from FortiPAM.
Regards,
Daniel
| User | Count |
|---|---|
| 2792 | |
| 1424 | |
| 812 | |
| 749 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.