Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dbg_algis
New Contributor

Fortigate and RDS server - block specific AD users only

Hello, We, currently, have few RDS servers. We want to block traffic to WAN only for specific users (not all) in specific RDS server. Naturally to do that we have to identify users somehow. I watched few CookBooks on Youtube (f. e. [link]https://www.youtube.com/watch?v=Il8u-3wJjfc).[/link] It's pretty simple (Authentificate users via Captive portal). However maybe someone knows how Fortigate works with RDS servers (one device and multiple users)? Will, Fortigate block only "required users" or it will "block all users" on user identified machine?

Another aproach is to simply migrate all "required to block users" to one server and remove "all not required to block users" from that server. However we try to avoid this approach.

Also if someone has ideas (another aproaches) – I'm listening.

Thanks.

1 REPLY 1
Alivo__FTNT
Staff
Staff

Hello,

one approach can be to place users you want to have access (or not) in specific AD group and

then allow or disallow such group in firewall policy. You can also chose not to monitor the specific

group for logon events. This way they won't have an auth session in FortiGate and won't match fw policy (unless there is some that would allow them without auth).

 

Best Regards,

Alivo

livo

Labels
Top Kudoed Authors