12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

User groups<br />

User<br />

A firewall user group can be used to provide override privileges for FortiGuard<br />

web filtering. See “Configuring FortiGuard override options for a user group” on<br />

page 391. For detailed information about FortiGuard Web Filter, including the<br />

override feature, see “FortiGuard - Web Filter” on page 435.<br />

Active Directory<br />

On a Microsoft Windows network, the <strong>FortiGate</strong> unit can allow access to members<br />

of Active Directory server user groups who have been authenticated on the<br />

Windows network. The Fortinet Server Authentication Extensions (FSAE) must be<br />

installed on the network domain controllers.<br />

An Active Directory user group provides access to a firewall policy that requires<br />

Active Directory type authentication and lists the user group as one of the allowed<br />

groups. The members of the user group are Active Directory groups that you<br />

select from a list that the <strong>FortiGate</strong> unit receives from the Windows AD servers<br />

that you have configured. See “Windows AD servers” on page 385.<br />

Note: An Active Directory user group cannot have FortiGuard Web Filter override privileges<br />

or SSL VPN access.<br />

SSL VPN<br />

An SSL VPN user group provides access to a firewall policy that requires<br />

SSL VPN type authentication and lists the user group as one of the allowed<br />

groups. Local user accounts, LDAP, and RADIUS servers can be members of an<br />

SSL VPN user group. The <strong>FortiGate</strong> unit requests the user’s user name and<br />

password when the user accesses the SSL VPN web portal. The user group<br />

settings include options for SSL VPN features. See “Configuring SSL VPN user<br />

group options” on page 392.<br />

An SSL VPN user group can also provide access to an IPSec VPN for dialup<br />

users. In this case, the IPSec VPN phase 1 configuration uses the Accept peer ID<br />

in dialup group peer option. The user’s VPN client is configured with the user<br />

name as peer ID and the password as pre-shared key. The user can connect<br />

successfully to the IPSec VPN only if the user name is a member of the allowed<br />

user group and the password matches the one stored on the <strong>FortiGate</strong> unit.<br />

Note: A user group cannot be an IPSec dialup group if any member is authenticated using<br />

a RADIUS or LDAP server.<br />

For more information, see “Creating a new phase 1 configuration” on page 345.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

388 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!