A firewall thinks in IP addresses, but security policy is written in terms of users and groups: "accounting may, others may not". (Fortinet Single Sign-On) lets FortiGate learn which user sits behind which IP and apply policy by AD group.
The user logs into the domain, the DC writes Event 4624, the Collector Agent reads the log and sends FortiGate a user-to-IP mapping. Groups come from LDAP, so policy is written by AD group. Blind spots: shared PCs, IP changes and non-domain devices.
Related topics in this course
- Event ID 4624 — the same logon event the builds the mapping from (Event ID reference).
- — HasSession answers the same question: who is logged on where (/course/tools/bloodhound-walkthrough).
- Tiering — group based policy is how you enforce tier separation at the network level too.
How it works
- The user logs into the domain — a normal logon, nothing new on the client.
- A on the DC (or a dedicated server) reads the security log and sees logon event 4624.
- The agent maps the user to the workstation IP and pushes that map to FortiGate (TCP, port 8000 by default).
- FortiGate applies policy by group: CN=Teachers → allow rule, CN=Students → deny rule.
Two operating modes
- Event Log / Polling mode — a on a dedicated server polls the DC for logon events.
- Kerberos-based — a light agent on every DC watches authentication; scales better.
- There is also Accounting based (for Wi-Fi) — same concept, a different source for the map.
Lab practice
- Install the on a Windows server in the corp.local lab domain. Create service account svc-fsso with a non-expiring password and only Event Log Readers rights — never Admin.
- In the set the DC, the FortiGate connection password and the port (8000 by default).
Now bind a FortiGate group to an group:
Then use the group in a policy (Policy & Objects → Firewall Policy → Source: FSSO-Teachers). Verify: from a workstation signed in as a Teachers member open a site — the session should appear under Security Fabric → User & Device → .
Risks and detection
- The account: compromise means log access and influence over the map. Minimal rights, monitor 4624 events for that account.
- Agent-to-FortiGate traffic is not a VPN — use an isolated management segment. This is Tier 0 communication.
- Stale mappings: a workstation shut down improperly leaves the user-to-IP pair alive until timeout. Account for this in sensitive rules.
Mitigation
- A dedicated management VLAN between FortiGate and the .
- Agent account: Event Log Readers plus Deny interactive logon.
- Regular audit: compare active sessions with real logons (quser / whoami on suspicious hosts).
- Sensitive rules (Tier 1 server access) — match not only the group but also the segment IP range.