Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlexW
New Contributor III

Fortiauthenticator and Windows RDS Gateway

Hi..

 

We want to use our Fortiauthenticator to provide 2FA with a Windows RDS gateway (2012). I cannot find any documentation on this so i was hoping someone else has figured this out..

 

I think i have to use the fortiauthenticator plugin for IIS/OWA, but how can i configure this plugin for the RDS Gateway ?

and is it even posible ?

 

Regards, Alex

 

 

Alex Wassink

NSE4,5,7,8 CCNP, ACMP, VCP6-NV

Alex Wassink NSE4,5,7,8 CCNP, ACMP, VCP6-NV
15 REPLIES 15
Locian
New Contributor

@AlexW

Just to make sure we are on the same ground I will describe the setup I have now. We have RD web access that leads to RD gateway. The user is authenticated using windows credentials on the RD web access login page ( I couldn't find a way to change this to NPS), after authentication the user is presented by the RD applications and once the user clicks on any of the applications (for example calc) an authentication window pop up which as per the configuration I have on the NPS is forwarded to the Fortiauthenticator.

 

After following debug on Fortiauthenticator I found that the authentication request doesn't have "User-Password" field and Fortiauthenticator rejects the request because of this.

 

You have mentioned in your message to Benji that you have installed Fortiauthenticator agent on RDP servers to enable token authentication, can you elaborate more on this? Do you think this can apply to my setup also?

 

Best Regards,

Ahmed

Huey
New Contributor III

Locian wrote:

@AlexW

Just to make sure we are on the same ground I will describe the setup I have now. We have RD web access that leads to RD gateway. The user is authenticated using windows credentials on the RD web access login page ( I couldn't find a way to change this to NPS), after authentication the user is presented by the RD applications and once the user clicks on any of the applications (for example calc) an authentication window pop up which as per the configuration I have on the NPS is forwarded to the Fortiauthenticator.

 

After following debug on Fortiauthenticator I found that the authentication request doesn't have "User-Password" field and Fortiauthenticator rejects the request because of this.

 

You have mentioned in your message to Benji that you have installed Fortiauthenticator agent on RDP servers to enable token authentication, can you elaborate more on this? Do you think this can apply to my setup also?

 

Best Regards,

Ahmed

Did you ever get this working?  I have exactly the same problem where the password is missing (according to the debug)

Layer8 Consulting

http://www.L8C.com

 

Layer8 Consulting http://www.L8C.com
Locian
New Contributor

Unfortunately no, after investigating this with Fortinet the final replay was that this is not supported now.

pbeall
New Contributor

I am also looking for this solution. However as usual it is very hard to find anyone else that has set it up!

jeff_painter1
New Contributor

We are looking at the same thing. Were you able to do this without VPN or some type of proxy for the Auth?

 

Thanks-Jeff

Rafael_Rosseto

Does anyone know if this feature request (FAC with RDS Gateway) has been released?

Labels
Top Kudoed Authors