11-20-2019 04:20 AM
Hi Team,
customer is managing all school students/schools in the country. currently they provide internet access to students via captive portal of fortigate. for every user they create a local account, so the student use these credentials to access the internet.
their current approach and since they have all users created by default in their Gsuite, is to let fortigate connect to Gsuite as an external directory. and let the students sign in to that captive portal using Gsuite logins. basically it is a SSO scenario between firewall and Gsuite. Fortinet are proposing Fotiauthenticator, which will play the role of SSO between Fortigate and the Gsuite.
we are trying to offer ISE for the same purpose. the idea is to offload authentication and captive portal from the firewall. questions:
- does ISE have the capability to add Gsuite as external authentication source?
- if yes, what is the optimum scenario? is it by keeping the captive portal on Fortigate and let fortigate connect with ISE for authentication?
- or removing all authentication proces from fortigate and configure captive portal on ISE and adding Gsuite as external authentication?
appreciate if anyone has had such a scenario to share it with me, and of course i'd like to brainstorm to come up with a great solution
thanks
Solved! Go to Solution.
11-25-2019 06:42 AM
Its likely possible if you can get it to work with SAML 2.0 like other providers at http://cs.co/ise-guest it hasn't been specifically tested but there are other SAML providers we don't test as well. I have copied @hslai and @howon as well to see what they think
11-22-2019 03:06 PM
11-23-2019 12:49 AM
11-25-2019 06:42 AM
Its likely possible if you can get it to work with SAML 2.0 like other providers at http://cs.co/ise-guest it hasn't been specifically tested but there are other SAML providers we don't test as well. I have copied @hslai and @howon as well to see what they think
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide