Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
R_F
Contributor

which one is priorty LDAP or FSSO

in a typical network with 500 workstations. I configured my FG 401F to work with my LDAP for authentication and at the same time explored the FSSO functionality while LDAP is still present.

Now, if the workstation will authenticate which method it will use LDAP or FSSO? Which method will take precedence first?

 

 

2 Solutions
ebilcari
Staff
Staff

FSSO can't replace LDAP. It's used as passive way of authentication to apply policies based on groups without requesting user's credentials again. More information can be found here: https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/450337/fsso

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

Sheikh
Staff
Staff

Hello @R_F 

 

Please check this article
https://community.fortinet.com/t5/FortiGate/Technical-Tip-An-explaination-of-mixed-policies-in-Firew....

 

- LDAP is an active authentication method, so users will need to enter the credentials to authenticate to Firewall, while FSSO is a passive authentication method.

- If it is not wanted that the users enter credentials to get resource access, it is suggested to use FSSO method (passive authentication).

- With LDAP authentication only, it is more logical to users enter credentials to get resource access.

 

So it all depends, where FSSO or LDAP authentication to be placed in Firewall. 

 

regards,

 

Sheikh

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**

View solution in original post

2 REPLIES 2
ebilcari
Staff
Staff

FSSO can't replace LDAP. It's used as passive way of authentication to apply policies based on groups without requesting user's credentials again. More information can be found here: https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/450337/fsso

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Sheikh
Staff
Staff

Hello @R_F 

 

Please check this article
https://community.fortinet.com/t5/FortiGate/Technical-Tip-An-explaination-of-mixed-policies-in-Firew....

 

- LDAP is an active authentication method, so users will need to enter the credentials to authenticate to Firewall, while FSSO is a passive authentication method.

- If it is not wanted that the users enter credentials to get resource access, it is suggested to use FSSO method (passive authentication).

- With LDAP authentication only, it is more logical to users enter credentials to get resource access.

 

So it all depends, where FSSO or LDAP authentication to be placed in Firewall. 

 

regards,

 

Sheikh

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
Labels
Top Kudoed Authors