【正文】
IP DstIP Prot SrcPort DstPort Data 6 12345 80 Get Trans Authentication ? A User object is a instance of an authentication method ? A User Group object is a container for User objects ? Identifies group members ? Protection Profile and Type provides authorization attributes for members ? FortiGate units control access to resources based on group membership ? The bination of User Group and Firewall Policy defines the authorization for a particular user ? Firewall Policy: VPN (SSL/IPSec/PPTP/L2TP), FWUA (firewall user authentication) Authentication – User/Server Types ? Local password file ? Username and password prompt ? RADIUS ? Username and password prompt ? LDAP / AD ? Username and password prompt ? FSAE / NTLM (AD) ? Single Sign On based on earlier authentication event ? PKI ? Certificate based authentication Authentication – Services ? Firewall Policies (Firewall User Authentication) ? SSL VPN ? IPSec VPN ? PPTP and L2TP ? Admin login ? FortiGuard Web Filtering Override Firewall Policies ? User Groups linked to Accept Firewall Policies ? On successful authentication a temporary rule is created ? If no traffic present rule remove after the ‘a(chǎn)uthtimeout’ ? Local, RADIUS, LDAP authentication presents user with a login page ? On successful authentication the user is redirected to requested site ? Windows AD (FSAE and NTLM) ? Authentication based on AD Group membership ? PKI user authenticated on presentation of a valid certificate ? HTTPS (and HTTP with redirect to HTTPS) SSL VPN ? User Groups are linked to SSL VPN policies ? Allows users access to the SSL VPN portal ? C