Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Vasya
New Contributor II

I add FSSO group in policy. It don't work.

Hello, guys! I have FortiGate 200D v5.6.2 build1486 (GA). I created proxy-policy. I add FSSO group there, but this policy don't work. The policy without FSSO group worked.  When I use "diagnose debug authd fsso list", I see correct FSSO logons.

When I use "diagnose debug enable" and "diagnose degug authd fsso server-status", I see my Server Name and Connection Status - connected. Help me please.

1 Solution
Vasya
New Contributor II

6 REPLIES 6
xsilver_FTNT
Staff
Staff

I would suggest following steps

1. flow debug - to check how the traffic from WKS pass the firewall and if intended policy with FSSO is tried to be used

2. packet capture/sniffer to verify source IP and traffic from WKS

3. check if policy matches traffic pattern

4. check if src IP address of the traffic matches to your FSSO records on FGT and that user does belong to firewall-fsso group in policy

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Vasya
New Contributor II

Sorry for my bad english.

[ol]
  • Traffic from Workstation pass to my explicit web proxy;
  • For test I checked one Workstation. It's my Workstation and I know IP address;
  • How do it?
  • User it is my AD account. My account member of AD group, that I add my explicit web proxy policy.[/ol]

    I created policy in "Policy & Objects -> Proxy Policy". Porxy type: Explicit web. Outgoing Interface: "WAN"(Internet).

    Enabled on: "LAN" interface. Source: IP address my Workstation and User group. Destination: all.

    As intermediary I use "Fortinet-Single-Sign-On Agent".

     

    When I delete "User group" from Source this Proxy Policy worked.

  • xsilver_FTNT

    try to check your config against this KB

    http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD36382

     

    !! and as you stated explicit proxy policy, then pay extra attention to "IP Based" part .. in CLI : set ip-based enable

    Because by default explicit proxy is session based and uses session cookies and not IP src/port to match traffic against FSSO user list.

     

    If this is not going to resolve, then I'd suggest to login to http://support.fortinet.com portal and open a technical trouble ticket for the issue and provide :

    - FGT config backup

    - outputs from FSSO troubleshooting [page 185] http://kb.fortinet.com/kb...ubleshooting-40-mr3pdf

    Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
    AAA, MFA, VoIP and other Fortinet stuff

    Vasya
    New Contributor II

    Version my FTG: v5.6.2 build1486 This version haven't "ip-based" command. 

    Vasya
    New Contributor II

    colhgts
    New Contributor

    This KB is exactly what I was looking for! It resolved the same issue I had with explicit proxy and FSSO in 5.6!

    Labels
    Top Kudoed Authors