Configuring A Directory Service Server - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

User

Configuring a Directory Service server

FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
You must install the Fortinet Server Authentication Extensions (FSAE) on the network and
configure the FortiGate unit to retrieve information from the Directory Service server. For
more information about FSAE, see the
To view the list of Directory Service servers, go to User > Directory Service.
Figure 411: Example Directory Service server list
Expand Arrow (Directory Service server)
Domain and groups
Create New
Name
AD Server
Domain
Groups
FSAE Collector IP
Delete icon
Edit icon
Add User/Group
Edit Users/Group
You need to configure the FortiGate unit to access at least one FSAE collector agent. You
can specify up to five Directory Service servers on which you have installed a collector
agent. If your FSAE collector agent requires authenticated access, you enter a password
for the server. The server name appears in the list of Directory Service servers when you
create user groups. You can also retrieve Directory Service information directly through an
LDAP server instead of through the FSAE agent.
Note: You can create a redundant configuration on your FortiGate unit if you install a
collector agent on two or more domain controllers. If the current (or first) collector agent
fails, the FortiGate unit switches to the next one in its list of up to five collector agents.
FSAE Technical
Add a new Directory Service server.
Select the Expand arrow beside the server/domain/group name to
display Directory Service domain and group information.
The name defined for the Directory Service server.
The domain name imported from the Directory Service server.
The group names imported from the Directory Service server.
The IP addresses and TCP ports of up to five FSAE collector agents
that send Directory Service server login information to the FortiGate
unit.
Delete this Directory Service server.
Edit this Directory Service server.
Add a user or group to the list. You must know the distinguished name
for the user or group.
Select users and groups to add to the list.
Directory Service
Note.
Delete
Edit User/Group
Edit
Add User/Group
663

Advertisement

Table of Contents
loading

Table of Contents