User
PKI
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
581
•
Configuring a Directory Service server
You need to configure the FortiGate unit to access at least one FSAE collector agent. You
can specify up to five Directory Service servers on which you have installed a collector
agent. If your FSAE collector agent requires authenticated access, you enter a password
for the server. The server name appears in the list of Directory Service servers when you
create user groups. You can also retrieve Directory Service information directly through an
LDAP server instead of through the FSAE agent.
You can enter information for up to five collector agents.
To add a new Directory Service server, go to
User > Directory Service,
select
Create New
,
and enter or select the following:
Figure 385: Directory Service server configuration
PKI
Public Key Infrastructure (PKI) authentication utilizes a certificate authentication library
that takes a list of peers, peer groups, and/or user groups and returns authentication
successful or denied notifications. Users only need a valid certificate for successful
authentication—no user name or password are necessary. Firewall and SSL VPN are the
only user groups that can use PKI authentication.
Add User/Group
Add a user or group to the list. You must know the distinguished name
for the user or group.
Edit Users/Group
Select users and groups to add to the list.
Note:
You can create a redundant configuration on your FortiGate unit if you install a
collector agent on two or more domain controllers. If the current (or first) collector agent
fails, the FortiGate unit switches to the next one in its list of up to five collector agents.
Name
Enter the name of the Directory Service server. This name appears in the list of
Directory Service servers when you create user groups.
FSAE Collector
IP/Name
Enter the IP address or name of the Directory Service server where this
collector agent is installed. The maximum number of characters is 63.
Port
Enter the TCP port used for Directory Service. This must be the same as the
FortiGate listening port specified in the FSAE collector agent configuration.
Password
Enter the password for the collector agent. This is required only if you
configured your FSAE collector agent to require authenticated access.
LDAP Server
Select the check box and select an LDAP server to access the Directory
Service.
Содержание Gate 60D
Страница 678: ...Reports Log Report FortiGate Version 4 0 Administration Guide 678 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 704: ...Index FortiGate Version 4 0 Administration Guide 704 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 705: ...www fortinet com...
Страница 706: ...www fortinet com...