Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
menatwork
New Contributor III

Fortigate AD Connection for userbased policies

Hi, 

I am trying to create policies based on AD-Users. So  I connected our FGT to our DC and was able to retrieve the users I would like to use in our policies.

 

If I create a policy (LAN->WAN) -> Source: Username of the AD User ->> Destination WAN (all Services) the connection is not working.

 

So I assume there is some component missing. As far as I understood, we will have to install the FSSO Agent on Windows AD and create a connection on our FGT to this SSO Agent, to authenticate our logged in PC-Users to the FGT  (=the FGT can check if the user is logged in correctly to AD).

 

Is this correct, or should the above mentioned, also work without any Clientsoftware in AD-Environment?

 

Thanks a lot!

1 Solution
ozkanaltas
Valued Contributor II

Hello @menatwork ,

 

Yes, you should use FSSO to achieve this request.

 

There are two types of FSSO for AD, with an agent, and without an agent.

 

On the agentless model, you can use FortiGate as a polling server. Fortigate can poll your AD server and learn who logged in.

 

With an agent, you need to install a Fortinet Single Sign-on agent on your ad or other server. Agent poll your AD server consolidate all login data and send to FortiGate.

 

And also my preference is the agent model.

 

You can review these links about agent and agentless models.

 

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/888827/poll-active-directory...

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-FSSO-in-DC-Agent-mode/ta-p/25299...

 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
1 REPLY 1
ozkanaltas
Valued Contributor II

Hello @menatwork ,

 

Yes, you should use FSSO to achieve this request.

 

There are two types of FSSO for AD, with an agent, and without an agent.

 

On the agentless model, you can use FortiGate as a polling server. Fortigate can poll your AD server and learn who logged in.

 

With an agent, you need to install a Fortinet Single Sign-on agent on your ad or other server. Agent poll your AD server consolidate all login data and send to FortiGate.

 

And also my preference is the agent model.

 

You can review these links about agent and agentless models.

 

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/888827/poll-active-directory...

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-FSSO-in-DC-Agent-mode/ta-p/25299...

 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Labels
Top Kudoed Authors