12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User<br />

Configuring user authentication<br />

User<br />

This section explains how to set up user accounts, user groups and external<br />

authentication servers. These are <strong>com</strong>ponents of user authentication that you can<br />

use to control access to network resources.<br />

This section describes:<br />

• Configuring user authentication<br />

• Local user accounts<br />

• RADIUS servers<br />

• LDAP servers<br />

• PKI authentication<br />

• Windows AD servers<br />

• User groups<br />

• Configuring peers and peer groups<br />

• Authentication settings<br />

Configuring user authentication<br />

<strong>FortiGate</strong> authentication controls access by user group, but creating user groups<br />

is not the first step in configuring authentication. You must configure user<br />

authentication in the following order:<br />

1 If external authentication using RADIUS or LDAP servers is needed, configure<br />

access to those servers. See “RADIUS servers” on page 381 and “LDAP servers”<br />

on page 382.<br />

2 Configure local user accounts in User > Local. For each user, you can choose<br />

whether the password is verified by the <strong>FortiGate</strong> unit, by a RADIUS server or by<br />

an LDAP server. See “Local user accounts” on page 380.<br />

3 If you use a Microsoft Windows Active Directory server for authentication,<br />

configure access to it. See “Configuring a Windows AD server” on page 386.<br />

Users authenticated by Active Directory server do not need local user accounts on<br />

the <strong>FortiGate</strong> unit. You must install the Fortinet Server Authentication Extensions<br />

(FSAE) on your Windows network.<br />

4 To use certificate-based authentication for administrative access (HTTPS GUI),<br />

IPSec, SSL-VPN, and web-based authentication, configure using User > PKI.<br />

See “Configuring PKI users” on page 385.<br />

5 Create user groups in User > User Group and add members. There are three<br />

types of user groups: Firewall, Active Directory and SSL VPN. See “Configuring a<br />

user group” on page 389.<br />

For PKI authentication, only Firewall and SSL VPN user groups are applicable.<br />

6 To change the authentication timeout value or select protocol support options, go<br />

to User > Authentication > Authentication. See “Authentication settings” on<br />

page 394.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 379

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!