Fortinet Fortinet 1.5 Скачать руководство пользователя страница 17

Using FSAE on your network 

Testing the configuration

Fortinet Server Authentication Extension Version 1.5 Technical Note
01-30005-0373-20071001

17

Allowing guests to access FSAE policies

Optionally, you can allow guest users to access FSAE firewall policies. Guests are 
users unknown to the Windows AD network and servers that do not log on to a 
Windows AD domain. To allow guest access, use the FortiGate GUI or CLI to 
specify a guest protection profile for your FSAE firewall policy. For example

config firewall policy

edit FSAE_policy

set fsae-guest-profile strict

end

You can specify any existing protection profile. If you prefer, you can create a 
custom protection profile to assign to guest users. For more information, see the 
Firewall Protection Profile chapter of the 

FortiGate Administration Guide

.

Testing the configuration

To verify that you have correctly configured FSAE on your network and on your 
FortiGate units:

1

From a workstation on your network, log on to your domain using an account that 
belongs to a group that is configured for authentication on the FortiGate unit.

2

Try to connect to the resource that is protected by the firewall policy requiring 
authentication via FSAE.

You should be able to connect to the resource without being asked for username 
or password.

3

Log off and then log on using an account that does not belong to a group you 
have configured for authentication on the FortiGate unit.

4

Try to connect to the resource that is protected by the firewall policy requiring 
authentication via FSAE.

Your attempt to connect to the resource should fail.

NTLM authentication

In system configurations where it is not possible to install FSAE clients on all AD 
servers, the FortiGate unit must be able to query the AD servers to find out if a 
user has been properly authenticated. This is achieved using the NTLM 
messaging features of Active Directory and Internet Explorer.

Understanding the NTLM authentication process

1

The client (user) attempts to connect to an external HTTP resource (internet) and 
issues an unauthenticated request via the FortiGate unit.

2

The FortiGate is aware that this client has not authenticated previously, so 
responds with a 

401 Unauthenticated

 status code, and tells the client which 

authentication method to come back with via the header: 

Proxy-Authenticated: NTLM

. The session is dismantled.

Содержание Fortinet 1.5

Страница 1: ...www fortinet com Fortinet Server Authentication Extension Version 1 5 T E C H N I C A L N O T E...

Страница 2: ...Trademarks Dynamic Threat Prevention System DTPS APSecure FortiASIC FortiBIOS FortiBridge FortiClient FortiGate FortiGate Unified Threat Management System FortiGuard FortiGuard Antispam FortiGuard Ant...

Страница 3: ...Ignore List 11 Configuring FortiGate group filters 11 To view the FortiGate Filter List 12 To configure a FortiGate group filter 12 Configuring TCP ports 13 Configuring FSAE on FortiGate units 14 Spe...

Страница 4: ...Fortinet Server Authentication Extension Version 1 5 Technical Note 4 01 30005 0373 20071001 Contents...

Страница 5: ...the FortiGate unit so that users automatically get access to permitted resources FortiGate units control access to resources based on user groups Through FSAE the Windows Active Directory AD groups ar...

Страница 6: ...t by the FSAE agent on the domain controller and if authentication is successful the information is then sent via the collector agent to the FortiGate unit Figure 2 NTLM FSAE implementation In Figure...

Страница 7: ...tor privileges and a password that does not expire Installing FSAE To install FSAE you must obtain the FortiClient Setup file from the Fortinet Support web site Perform the following installation proc...

Страница 8: ...e able to authenticate to FortiGate units using FSAE You can also do this later See Configuring FSAE on Windows AD on page 8 15 Select Next 16 Optionally clear the check boxes of domain controllers on...

Страница 9: ...Professional Configuring Windows AD server user groups FortiGate units control access at the group level All members of a group have the same network access as defined in FortiGate firewall policies Y...

Страница 10: ...st Exclude users such as system accounts that do not authenticate to any FortiGate unit See Configuring the Global Ignore List on page 11 FortiGate Group Filter Configure group filtering for each Fort...

Страница 11: ...nada Timers Workstation verify interval Enter the interval in minutes at which FSAE checks whether the user is still logged in The default is every 5 minutes If ports 139 or 445 cannot be opened on yo...

Страница 12: ...te If no filter is defined for a FortiGate unit and there is no default filter the collector agent sends all Windows AD group and user logon events to the FortiGate unit While this normally is not a p...

Страница 13: ...rs on page 11 in the Configuring collector agent settings section Default Select to create the default filter The default filter applies to any FortiGate unit that does not have a specific filter defi...

Страница 14: ...sses these servers in the order that they appear in the list If a server becomes unavailable the unit accesses the next one in the list To specify collector agents 1 Go to User Windows AD and select C...

Страница 15: ...hould be belong to only one FortiGate user group If you assign it to multiple FortiGate user groups the FortiGate unit recognizes only the last user group assignment To create a user group for FSAE au...

Страница 16: ...ting firewall policies Policies that require FSAE authentication are very similar to other firewall policies Currently only one single authentication firewall policy can be configured if the source in...

Страница 17: ...ortiGate unit 2 Try to connect to the resource that is protected by the firewall policy requiring authentication via FSAE You should be able to connect to the resource without being asked for username...

Страница 18: ...oded with the client password it may contain the challenge nonce twice using different algorithms 6 The FortiGate unit checks with the FSAE client over port 8000 to see if the authentication hash matc...

Страница 19: ...www fortinet com...

Страница 20: ...www fortinet com...

Отзывы: