User Group List - Fortinet Fortigate-5000 series Administration Manual

Hide thumbs Also See for Fortigate-5000 series:
Table of Contents

Advertisement

User

User group list

FortiGate Version 3.0 MR4 Administration Guide
01-30004-0203-20070102
Active Directory
On a Microsoft Windows network, the FortiGate unit can allow access to members
of Active Directory server user groups who have been authenticated on the
Windows network. The Fortinet Server Authentication Extensions (FSAE) must be
installed on the network domain controllers.
An Active Directory user group provides access to a firewall policy that requires
Active Directory type authentication and lists the user group as one of the allowed
groups. The members of the user group are Active Directory groups that you
select from a list that the FortiGate unit receives from the Windows AD servers
that you have configured. See
Note: An Active Directory user group cannot have FortiGuard Web Filter override privileges
or SSL VPN access.
SSL VPN
An SSL VPN user group provides access to a firewall policy that requires
SSL VPN type authentication and lists the user group as one of the allowed
groups. Local user accounts, LDAP, and RADIUS servers can be members of an
SSL VPN user group. The FortiGate unit requests the user's user name and
password when the user accesses the SSL VPN web portal. The user group
settings include options for SSL VPN features. See
group options" on page
332.
An SSL VPN user group can also provide access to an IPSec VPN for dialup
users. In this case, the IPSec VPN phase 1 configuration uses the Accept peer ID
in dialup group peer option. The user's VPN client is configured with the user
name as peer ID and the password as pre-shared key. The user can connect
successfully to the IPSec VPN only if the user name is a member of the allowed
user group and the password matches the one stored on the FortiGate unit.
Note: A user group cannot be an IPSec dialup group if any member is authenticated using
a RADIUS or LDAP server.
For more information, see
Go to User > User Group to configure user groups.
Figure 214:User group list
Create New
Add a new user group.
Group Name
The name of the user group. User group names are listed by type of
user group: Firewall, Active Directory and SSL VPN.
Members
The users, RADIUS servers, or LDAP servers in the user group.
"Windows AD servers" on page
"Configuring SSL VPN user
"Creating a new phase 1 configuration" on page
User group
326.
287.
329

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents