Fortinet black logo

Administration Guide

Configure FortiDeceptor for admin access authentication from Active Directory

Copy Link
Copy Doc ID 666526c9-6f4b-11ed-8e6d-fa163e15d75b:170108
Download PDF

Configure FortiDeceptor for admin access authentication from Active Directory

To configure FortiDeceptor to authenticate from the Active Directory (AD) server, prepare and import a signed server certificate into FortiAuthenticator. Next you will configure the LDAP service and add the local user to the LDAP directory tree in FortiAuthenticator. Then you will import the server certificate and configure the LDAP server in FortiDeceptor.

FortiDeceptor admin access authentication from FortiAuthenticator

To configure FortiDeceptor admin access authentication front FortiAuthenticator using LDAP:
  1. Prepare the certificate.
  2. Import the signed server certificate to FortiAuthenticator.
  3. Import the RootCA to FortiAuthenticator.
  4. Configure the FortiAuthenticator LDAP Service.
  5. Add the local user the LDAP Directory Tree.
  6. Import the RootCA into FortiDeceptor.
  7. Configure the LDAP server in FortiDeceptor.

1. Prepare the certificate

If you are not using LDAP, you can proceed directly to Step 5: Create LDAP Directory Tree.

To prepare the certificate:
  1. Create a Certificate Signing Request (CSR) and private key.
  2. Sign the CSR with either a public Certifcate Authority (CA) or your own RootCA. For the purpose of this example, we will be using a self-created RootCA.

2. Import the signed server certificate to FortiAuthenticator

  1. Log in to FortiAuthenticator.
  2. Go to Certificate Management > End Entities > Local Services and click Import.

  3. Select Choose File to locate the certificate file on your computer.
  4. Select OK to import the certificate.

For more information, see Certificate Management > End Entities in the FortiAuthenticator Administration Guide.

3. Import the RootCA to FortiAuthenticator

  1. Go to Certificate Management > Certificate Authorities > Local CAs.
  2. Click Create New and configure the certificate settings.
  3. Click OK to create the new certificate.

For more information, see Certificate Management > Certifcate Authorities > Local CAs in the FortiAuthenticator Administration Guide.

4. Configure the FortiAuthenticator LDAP Service

  1. In FortiAuthenticator, go to Authentication > LDAP Service > General.
  2. From the LDAP server certificate dropdown, select the server certificate you imported.
  3. From the CA certificate that issued the server certificate dropdown, select RootCA and click OK.

5. Add the local user the LDAP Directory Tree

  1. In FortiAuthenticator, from the LDAP directory tree, select the green plus (+) symbol next to the DN entry where you want to add the node. The Create New LDAP Entry window opens.

  2. In the Class field, select the identifier to use.
  3. Select the required value from the dropdown menu, or select Create New to create a new entry of the selected class.
  4. Click OK.

For more information, see Creating the directory tree in the in the FortiAuthenticator Administration Guide.

6. Import the RootCA into FortiDeceptor

If you are not using LDAP, proceed to Step 7. Configure the LDAP server in FortiDeceptor.

  1. In FortiDeceptor, go to System > Certificates and click Import.
  2. In the Certifcate field, click Browse and upload a copy of the RootCA certificate you imported to FortiAuthenticator in Step 3 Import the RootCA to FortiAuthenticator.
  3. Configure the rest of the certificate settings and click OK.

For more information, see Certificates.

7. Configure the LDAP server in FortiDeceptor

  1. In FortiDeceptor, go to System > LDAP servers and click Create New. The New LDAP Server page opens.
  2. Configure the LDAP settings keeping the following considerations in mind:
    Common NameThe Common Name must match the node you created in the LDAP tree.
    Enable Secure ConnectionWhen enabled, you must select the RootCA you imported from the CA Certificate dropdown.

  3. Click OK.

Configure FortiDeceptor for admin access authentication from Active Directory

To configure FortiDeceptor to authenticate from the Active Directory (AD) server, prepare and import a signed server certificate into FortiAuthenticator. Next you will configure the LDAP service and add the local user to the LDAP directory tree in FortiAuthenticator. Then you will import the server certificate and configure the LDAP server in FortiDeceptor.

FortiDeceptor admin access authentication from FortiAuthenticator

To configure FortiDeceptor admin access authentication front FortiAuthenticator using LDAP:
  1. Prepare the certificate.
  2. Import the signed server certificate to FortiAuthenticator.
  3. Import the RootCA to FortiAuthenticator.
  4. Configure the FortiAuthenticator LDAP Service.
  5. Add the local user the LDAP Directory Tree.
  6. Import the RootCA into FortiDeceptor.
  7. Configure the LDAP server in FortiDeceptor.

1. Prepare the certificate

If you are not using LDAP, you can proceed directly to Step 5: Create LDAP Directory Tree.

To prepare the certificate:
  1. Create a Certificate Signing Request (CSR) and private key.
  2. Sign the CSR with either a public Certifcate Authority (CA) or your own RootCA. For the purpose of this example, we will be using a self-created RootCA.

2. Import the signed server certificate to FortiAuthenticator

  1. Log in to FortiAuthenticator.
  2. Go to Certificate Management > End Entities > Local Services and click Import.

  3. Select Choose File to locate the certificate file on your computer.
  4. Select OK to import the certificate.

For more information, see Certificate Management > End Entities in the FortiAuthenticator Administration Guide.

3. Import the RootCA to FortiAuthenticator

  1. Go to Certificate Management > Certificate Authorities > Local CAs.
  2. Click Create New and configure the certificate settings.
  3. Click OK to create the new certificate.

For more information, see Certificate Management > Certifcate Authorities > Local CAs in the FortiAuthenticator Administration Guide.

4. Configure the FortiAuthenticator LDAP Service

  1. In FortiAuthenticator, go to Authentication > LDAP Service > General.
  2. From the LDAP server certificate dropdown, select the server certificate you imported.
  3. From the CA certificate that issued the server certificate dropdown, select RootCA and click OK.

5. Add the local user the LDAP Directory Tree

  1. In FortiAuthenticator, from the LDAP directory tree, select the green plus (+) symbol next to the DN entry where you want to add the node. The Create New LDAP Entry window opens.

  2. In the Class field, select the identifier to use.
  3. Select the required value from the dropdown menu, or select Create New to create a new entry of the selected class.
  4. Click OK.

For more information, see Creating the directory tree in the in the FortiAuthenticator Administration Guide.

6. Import the RootCA into FortiDeceptor

If you are not using LDAP, proceed to Step 7. Configure the LDAP server in FortiDeceptor.

  1. In FortiDeceptor, go to System > Certificates and click Import.
  2. In the Certifcate field, click Browse and upload a copy of the RootCA certificate you imported to FortiAuthenticator in Step 3 Import the RootCA to FortiAuthenticator.
  3. Configure the rest of the certificate settings and click OK.

For more information, see Certificates.

7. Configure the LDAP server in FortiDeceptor

  1. In FortiDeceptor, go to System > LDAP servers and click Create New. The New LDAP Server page opens.
  2. Configure the LDAP settings keeping the following considerations in mind:
    Common NameThe Common Name must match the node you created in the LDAP tree.
    Enable Secure ConnectionWhen enabled, you must select the RootCA you imported from the CA Certificate dropdown.

  3. Click OK.