Create a user
Use the Users/Groups Creation Wizard to create user accounts. From the User Definition page, select Create New to start the wizard.
To create a local user:
-
In the User Type page, select Local User and then select Next.
-
In the Login Credentials page, enter a user name and password for the new user and then select Next.
-
In the Contact Info page, enter an email address for the user and then select Next. Alternatively, you can supply the userʼs SMS contact information. To assign a FortiToken to the user, enable Two-factor Authentication and select a token from the drop-down menu provided. The Contact Info page is optional.
-
In the Extra Info page, select Enabled to make the new user active. To place the user into a group, enable User Group and then select a group from the drop-down menu. For information on user groups, see Create or edit a user group.
-
Select Submit to create the new local user.
To create a remote RADIUS user:
-
In the User Type page, select Remote RADIUS User and then select Next.
-
In the RADIUS Server page, enter a user name, select a RADIUS server from the drop-down menu, and then select Next. For information on RADIUS servers, see Create or edit a RADIUS server.
-
In the Contact Info page, enter an email address for the user and then select Next. Alternatively, you can supply the userʼs SMS contact information. To assign a FortiToken to the user, enable Two-factor Authentication and select a token from the drop-down menu provided. The Contact Info page is optional.
-
In the Extra Info page, select Enabled to enable the new user. To place the user into a group, enable User Group and then select a group from the drop-down menu. For information on user groups, see Create or edit a user group.
-
Select Submit to create the new RADIUS user.
To create a remote TACACS+ user:
By default, the TACACS+ Servers option under User & Device is not visible unless you add a server using the following CLI command: config user tacacs+ edit <name> set server <IP_address> next end |
-
In the User Type page, select Remote TACACS+ User and then select Next.
-
In the TACACS+ Server page, enter a user name, select a TACACS+ server from the drop-down menu, and then select Next. For information on TACACS+ servers, see Create or edit a TACACS server
-
In the Contact Info page, enter an email address for the user and then select Next. Alternatively, you can supply the userʼs SMS contact information. To assign a FortiToken to the user, enable Two-factor Authentication and select a token from the drop-down menu provided. The Contact Info page is optional.
-
In the Extra Info page, select Enabled to enable the new user. To place the user into a group, enable User Group and then select a group from the drop-down menu. For information on user groups, see Create or edit a user group.
-
Select Submit to create the new TACACS+ user.
To create a remote LDAP user:
-
In the User Type page, select Remote LDAP User and then select Next.
-
In the LDAP Server page, select an existing LDAP server from the drop-down menu or create an LDAP server and then select Next. To create an LDAP server, select the Create New icon in the drop-down menu, enter the required information, and then click OK. For information on LDAP servers, see Create or edit an LDAP server.
-
In the Remote Users page, enter and apply the LDAP filter, enter a search term to search the server, and select a user from the results.
-
Select Submit to create the remote LDAP user.
To use Fortinet Single Sign-On (FSSO):
-
In the User Type page, select FSSO and then select Next.
-
In the Remote Groups page, select the FSSO agent, select an AD group, and then select Next.
To create an AD group, see To create an AD group:.
-
In the Local Group page, select Choose Existing or Create New.
If you select Choose Existing, select the FSSO group name from the drop-down menu.
If you select Create New, enter the name of the FSSO group in the field.
-
Select Submit to use FSSO.
-
Click OK in the confirmation dialog box.
To create an AD group:
config user adgrp
edit <AD_group_name>
set server-name <FSSO_agent_name>
next
end
For example:
config user adgrp
edit adgroup1
set server-name NewFSSOserver
next
end
To enable DNS service lookup:
config user domain-controller edit "win2016" set ad-mode ds set dns-srv-lookup enable set hostname "win2016" set username "replicate" set password ********** set domain-name "SMB2016.LAB" next end
To specify the source IP and port for the fetching domain controller:
config user domain-controller edit "win2016" set ad-mode ds set hostname "win2016" set username "replicate" set password ********** set ip-address 172.18.52.188 set source-ip-address 172.16.100.1 set source-port 2000 set domain-name "SMB2016.LAB" next end
To use an LDAP server as a credential store:
-
Configure the LDAP server:
config user ldap edit "openldap" set server "172.18.60.214" set cnid "cn" set dn "dc=qafsso,dc=com" set type regular set username "cn=Manager,dc=qafsso,dc=com" set password ********** set antiphish enable set password-attr "userPassword" next end
-
Configure the web filter profile:
config webfilter profile edit "webfilter" config ftgd-wf unset options config filters edit 1 set action block next end end config antiphish set status enable config inspection-entries edit "cat34" set fortiguard-category 34 set action block next end set authentication ldap set ldap "openldap" end set log-all-url enable next end
To configure Active Directory in LDS mode:
config user domain-controller edit "win2016adlds" set ad-mode lds set hostname "win2016adlds" set username "foo" set password ********** set ip-address 192.168.10.9 set domain-name "adlds.local" set adlds-dn "CN=adlds1part1,DC=ADLDS,DC=COM" set adlds-ip-address 192.168.10.9 set adlds-port 3890 next end