Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kpiimis
New Contributor

Multiple RDP Users using each different policy

Hi Good Day!

 

Is it possible to let RDP users have their own policy?

e.g

User A -> Policy A with with user A as source 

User B -> policy B with with user B as source 

i was able to setup LDAP to authenticate the users but when User A and B simultaneously login on RDP, they only using the policy A if users A login first and vice versa.  they cant use their respective policy.

3 REPLIES 3
lobstercreed
Valued Contributor

Hi Gilbert,

 

Did you ever get this figured out?  Something isn't configured right on the policies, but I'm not sure I'm understanding what you're seeing. 

 

What I would envision doing (assuming this is a VPN policy you're talking about?) is create a policy from interface ssl.root to interface lan with a destination address matching only the destination PC for user A.  The service of course is RDP (3389), and the source matches your tunnel address range AND the user A definition on your firewall.  Then duplicate this for user B, with the only differences being the destination address and the user in the source part of the policy. 

 

With that configuration I don't see how they could possibly be hitting the wrong policies because something wouldn't match.  I'm thinking you're basing something on a group or a range of addresses, but I'm not sure.  Feel free to provide more info so we can help better.

 

- Daniel

kpiimis

Hi Daniel,

 

I forgot to mentioned that the users here are using zero client device to connect to the RDP Server. they are not using VPN. so these zero client devices have their own Private IP (vlan 1, vlan 2 etc..) to connect the server (vlan 10 with address 10.10.10.9) thru RDP Session . when these zero client are connected to the RDP they are suppose to reach the internet using their configured department policy. unfortunately all users regardless of what source address or OU or vlan fall on 1 policy depending on the first user who established the RDP session first

 

Moreover, these users/zero client devices are using RDP Session on the server to reach the internet.

lobstercreed

I'm definitely not wrapping my head around this properly.  Probably just a matter of having never done anything like it.  Maybe a network drawing would help showing what traffic passes through the FortiGate, etc.

 

Also, do you have a FortiAnalyzer?  Logging the traffic might help you see what's happening and why (maybe it's not what it seems).  I just don't see how which user logs in first would make any difference if you're using firewall users.  Maybe if you're using FSSO, but that's a whole different story.

 

I do offer some consulting via remote session (Zoom or TeamViewer) for a reasonable fee if you want me to have a look and help you get it figured out.  You can PM me for details.

Labels
Top Kudoed Authors