配置 LDAP 支持

用户认证

 

 

3 输入 RADIUS 服务器的名称。

您可以输入任何名称。此用户名可以包括数字 (0-9),大写和小写字母 (A-Z,a-z), 以及特殊字符 - 和 _。不能使用其它特殊字符和空格符。

4 输入 RADIUS 服务器的域名 或者 IP 地址

5 输入 RADIUS 服务器 密码

6 单击

图 18: RADIUS 配置举例

删除 RADIUS 服务器

您不能删除已经添加到用户组的 RADIUS 服务器。

1 进入用户 > RADIUS

2 对您要删除的 RADIUS 服务器,单击服务器名旁边的 删除

3 单击

配置 LDAP 支持

如果您配置了 LDAP 支持,当某个用户被配置为要求使用 LDAP 服务器认证的时候, FortiGate 将连接 LDAP 服务器以获得认证。要通过 FortiGate 设备进行认证,这个用 户需要输入一个用户名和对应的密码。FortiGate 将拥护名和密码发送到 LDAP 服务 器。如果 LDAP 服务器认证了这个用户,那么用户即可成功地通过 FortiGate 设备的认 证。如果 LDAP 服务器不能认证这个用户,FortiGate 设备将拒绝这个连接。

FortiGate 设备支持 RFC2251 定义的 LDAP 协议功能,用于搜索有效的用户名和密 码。ForitGate LDAP 支持所有兼容于 LDAP v3 的 LDAP 服务器。

FortiGate LDAP 支持不包括 LDAP 的扩展功能,例如某些 LDAP 服务器的密码到期 通知功能。FortiGate LDAP 支持不为用户提供有关认证失败的原因等信息。

PPTP, L2TP, IPSec VPN 和防火墙认证都支持 LDAP 用户认证。 PPTP, L2TP, 和

IPSec VPN 支持 PAP ( 包认证协议 ),但不支持 CHAP ( 挑战 - 握手协议 )。

本节描述了以下内容:

·添加 LDAP 服务器

·删除 LDAP 服务器

176

美国飞塔有限公司

Page 188
Image 188
Fortinet 500 manual 配置 Ldap 支持, 删除 Radius 服务器, 176, 输入 Radius 服务器的域名 或者 IP 地址。, 进入用户 Radius。

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.