Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
megaali3000
New Contributor

Two separate groups in AD, with two internet uplinks?

Good day everyone,

we have an active directory with FSSO agent installed on it and two groups inside it, for example Group1 and Group2. and we have two internet connected to our fortigate interfaces.

now we want to restrict the groups to use only one exact internet (Group 1 ---> internet1, Group2 ---> internet2) and if one of the links disconnected we want the group that their internet was shut, switch to to connected link automatically.

And the problem is the users might logon to their pc anywhere in the network so I don't think using policy routes would help us.

I would be glad to hear your suggestions.

 
2 REPLIES 2
Nikhil_Chaudhari
New Contributor

Hi,

you can achieve this via sd-wan rules by configuring sd-wan on firewall.

Nikhil Chaudhari
Nikhil Chaudhari
megaali3000

nklchdr wrote:

Hi,

you can achieve this via sd-wan rules by configuring sd-wan on firewall.

No the problem is SD-WAN doesn't support FSSO groups, and you don't have the ability to restrict a group to only use one internet link.

Labels
Top Kudoed Authors