12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User groups<br />

User<br />

Configuring a Windows AD server<br />

Go to User > Windows AD and select Create New or the Edit icon of an existing<br />

Windows AD server.<br />

Figure 262:Windows AD server configuration<br />

Name<br />

Type or edit the name of the Windows AD server. This name appears in<br />

the list of Windows AD servers when you create user groups.<br />

Enter the following information for up to five collector agents.<br />

FSAE Type or edit the IP address of the Windows AD server where this<br />

Collector IP collector agent is installed.<br />

Port Type or edit the TCP port used for Windows AD. This must be the same<br />

as the <strong>FortiGate</strong> listening port specified in the FSAE collector agent<br />

configuration.<br />

Password Type or edit the password for the collector agent. This is required only if<br />

you configured your FSAE collector agent to require authenticated<br />

access.<br />

User groups<br />

A user group is a list of user identities. An identity can be:<br />

• a local user account (user name and password) stored on the <strong>FortiGate</strong> unit<br />

• a local user account with a password stored on a RADIUS or LDAP server<br />

• a RADIUS or LDAP server (all identities on the server can authenticate)<br />

• a user group defined on a Microsoft Active Directory server<br />

In most cases, the <strong>FortiGate</strong> unit authenticates users by requesting their user<br />

name and password. The <strong>FortiGate</strong> unit checks local user accounts first. If a<br />

match is not found, the <strong>FortiGate</strong> unit checks the RADIUS or LDAP servers that<br />

belong to the user group. Authentication succeeds when a matching user name<br />

and password are found.<br />

For an Active Directory user group, the Active Directory server authenticates<br />

users when they log on to the network. The <strong>FortiGate</strong> unit receives the user’s<br />

name and IP address from the FSAE collector agent. For more information about<br />

FSAE, see the FSAE Technical Note.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

386 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!