You can configure an Active Directory (AD) connector that acts as a proxy between the AD server and EMS.
The following shows an example environment, which consists of the following virtual machines (VM):
- VM1: EMS
- VM2: AD server (ems104.com)
- VM3: AD connector
In this example, VM2 is connected to a local network with an IP address of 192.168.178.14/24. EMS is connected to a public network with an IP address of 10.71.5.77/24. In this scenario, when you attempt to add the AD server as an authentication server in Administration > Authentication Servers in EMS, it cannot reach the AD server. The AD connector solves this problem. The AD connector has the following network adapters:
The gateway for adapter data is 192.168.1.1, which is a FortiGate that is connected to the Internet. The AD server cannot directly connect to EMS. EMS cannot access the AD server. The connector serves as a proxy to add the AD server to EMS.
To configure the AD connector:
- Add an API key:
- In EMS, go to Administration > Authentication Servers.
- Click Connectors.
- Click API Keys, then Add. Add a new API key.
- Create the AD connector:
- You can install the AD connector in a host that EMS and the AD server can reach. On the host machine, from the EMS installation package, run FortiClientEndpointManagementServerADConnector_7.2.0.XXXX_x64.msi.
- In the Connect to EMS Configuration dialog, enter the EMS IP address, fully qualified domain name, or account ID in the EMS IP/FQDN/Account ID field.
- In the EMS Port field, enter the port number.
- In the Connector UID field, enter the AD connector UID.
- In the Connector Api Key field, enter the API key value.
- Click Add Site, and enter the EMS site information. Ensure that a Connection established message displays, then click Next.
- Go to Administration > Authentication Servers > Connectors to confirm that you successfully created an AD connector.
- Go to Administration > Authentication Servers.
- Enable Use Connector.
- From the Connector dropdown list, select the AD connector.
- Save the configuration. EMS successfully adds the AD server as an authentication server.