Fortinet white logo
Fortinet white logo

Cookbook

FortiGate user management

FortiGate user management

Once user authentication is successful on FortiAuthenticator, it sends a SAML assertion back to the client with the username and group information. When the client redirects this information to the FortiGate SAML SP, the FortiGate must process the assertion and match the correct user group for access control.

To configure user groups for Finance and Sales in FortiGate:
  1. Go to User & Authentication > User Groups and select Create New.
  2. To create a user group for Sales:
    1. In Name, enter Sales.
    2. In Remote Groups, click Add.
    3. Choose the SAML SSO settings as the Remote Server.
    4. Set Groups to Specify and enter the group name CN=Sales,CN=Users,DC=fortiad,DC=info.
    5. Click OK.

  3. To create a user group for Finance:
    1. In Name, enter Finance.
    2. In Remote Groups, click Add.
    3. Choose the SAML SSO settings as the Remote Server.
    4. Set Groups to Specify.

      The group name is the result of the output of the LDAP query for the memberOf attribute. In the example, this is CN=Finance,CN=Users,DC=fortiad,DC=info.

    5. Click OK.

  4. Besides the groups for SAML users, a non-SAML placeholder group needs to be created in order for SSL VPN portal to be active. The following shows a placeholder group named sslvpn_group with 2 local users.

FortiGate user management

FortiGate user management

Once user authentication is successful on FortiAuthenticator, it sends a SAML assertion back to the client with the username and group information. When the client redirects this information to the FortiGate SAML SP, the FortiGate must process the assertion and match the correct user group for access control.

To configure user groups for Finance and Sales in FortiGate:
  1. Go to User & Authentication > User Groups and select Create New.
  2. To create a user group for Sales:
    1. In Name, enter Sales.
    2. In Remote Groups, click Add.
    3. Choose the SAML SSO settings as the Remote Server.
    4. Set Groups to Specify and enter the group name CN=Sales,CN=Users,DC=fortiad,DC=info.
    5. Click OK.

  3. To create a user group for Finance:
    1. In Name, enter Finance.
    2. In Remote Groups, click Add.
    3. Choose the SAML SSO settings as the Remote Server.
    4. Set Groups to Specify.

      The group name is the result of the output of the LDAP query for the memberOf attribute. In the example, this is CN=Finance,CN=Users,DC=fortiad,DC=info.

    5. Click OK.

  4. Besides the groups for SAML users, a non-SAML placeholder group needs to be created in order for SSL VPN portal to be active. The following shows a placeholder group named sslvpn_group with 2 local users.