User Authentication: Local, LDAP/RADIUS & SSO

FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)

مقصدObjectiveObjective

اس لیب میں آپ لوکل یوزرز اور گروپس بنائیں گے، FortiGate کو LDAP اور RADIUS سرورز سے جوڑیں گے، FSSO/SSO کانسیپٹس سمجھیں گے اور یوزر بیسڈ فائر وال پالیسیز نافذ کریں گے۔Is lab mein aap local users aur groups banayenge, FortiGate ko LDAP aur RADIUS servers se jorenge, FSSO/SSO concepts samjhenge aur user-based firewall policies nafiz karenge.In this lab you will create local users and groups, connect FortiGate to LDAP and RADIUS servers, understand FSSO/SSO concepts, and enforce user-based firewall policies.

آسان مثالSimple AnalogySimple Analogy

یوزر آتھینٹیکیشن ایسے ہے جیسے سوسائٹی میں ممبر کارڈ کی چیکنگ: گارڈ پہلے چیک کرتا ہے کہ آپ کون ہیں (لاگ اِن)، پھر آپ کی ممبر کیٹیگری (گروپ) دیکھ کر فیصلہ کرتا ہے کہ کون سی سہولتیں (پالیسیز) استعمال کر سکتے ہیں۔User authentication aise hai jaise society mein member card ki checking: guard pehle check karta hai ke aap kaun hain (login), phir aap ki member category (group) dekh kar faisla karta hai ke kaun si sahoolaten (policies) istemal kar sakte hain.User authentication is like the society's member card check: guards first check who you are (login), then check your member category (group) to decide which facilities you can use (policies).

سیٹ اپLab SetupLab Setup

fg-03 والی FortiGate استعمال کریں۔ لیب ڈائریکٹری سرور (LDAP) 192.168.10.50 پر، RADIUS سرور 192.168.10.51 پر۔ ٹیسٹ یوزر: labuser۔fg-03 wali FortiGate istemal karen. Lab directory server (LDAP) 192.168.10.50 par, RADIUS server 192.168.10.51 par. Test user: labuser.Use the fg-03 FortiGate. Lab directory server (LDAP) at 192.168.10.50, RADIUS server at 192.168.10.51. Test user: labuser.

اقداماتStepsSteps

Step 1

FortiGate پر لوکل یوزر بنائیں۔ چھوٹی سیٹ اپس اور ڈائریکٹری سے جوڑنے سے پہلے ٹیسٹنگ کے لیے لوکل یوزرز ٹھیک ہیں۔FortiGate par local user banayen. Choti setups aur directory se jorne se pehle testing ke liye local users theek hain.Create a local user on the FortiGate. Local users are fine for small setups and for testing before connecting to a directory.

config user local
    edit labuser
        set type password
        set passwd LabUser123!
    next
end

🖱️ User & Authentication > User Definition میں Create New > Local User پر جائیں۔User & Authentication > User Definition mein Create New > Local User par jayen.Go to User & Authentication > User Definition, Create New > Local User.

Step 2

یوزر گروپ بنائیں اور یوزر کو شامل کریں۔ پالیسیز گروپ پر میچ ہوتی ہیں، انفرادی یوزر پر نہیں — تو رسائی گروپ کے حساب سے مینیج ہوتی ہے۔User group banayen aur user ko shamil karen. Policies group par match hoti hain, infiradi user par nahi — to rasai group ke hisab se manage hoti hai.Create a user group and add the user. Policies match groups, not single users — so access is managed per group.

config user group
    edit LAN_USERS
        set member labuser
    next
end

🖱️ User & Authentication > User Groups میں Create New > User Group پر جائیں۔User & Authentication > User Groups mein Create New > User Group par jayen.Go to User & Authentication > User Groups, Create New > User Group.

Step 3

گروپ شامل کر کے LAN-to-WAN پالیسی کو یوزر ایویر بنائیں۔ اب صرف LAN_USERS کے آتھینٹی کیٹڈ ممبرز براؤز کر سکیں گے۔Group shamil kar ke LAN-to-WAN policy ko user-aware banayen. Ab sirf LAN_USERS ke authenticated members browse kar sakenge.Make the LAN-to-WAN policy user-aware by adding the group. Now only authenticated members of LAN_USERS can browse.

config firewall policy
    edit 1
        set groups LAN_USERS
    next
end

🖱️ Policy & Objects > Firewall Policy میں پالیسی ایڈٹ کریں اور Source > User میں گروپ شامل کریں۔Policy & Objects > Firewall Policy mein policy edit karen aur Source > User mein group shamil karen.Edit the policy under Policy & Objects > Firewall Policy and add the group under Source > User.

Step 4

FortiGate کو کمپنی کی LDAP ڈائریکٹری سے جوڑیں۔ cnid بتاتا ہے کہ یوزر نیم کون سا ایٹریبیوٹ ہے، dn وہ جگہ ہے جہاں یوزرز تلاش کیے جاتے ہیں، اور بائنڈ اکاؤنٹ ڈائریکٹری پڑھتا ہے۔FortiGate ko company ki LDAP directory se joren. cnid batata hai ke username kaun sa attribute hai, dn woh jagah hai jahan users talash kiye jate hain, aur bind account directory parhta hai.Connect FortiGate to the company's LDAP directory. cnid tells FortiGate which attribute is the username, dn is where users are searched, and the bind account reads the directory.

config user ldap
    edit AD-LAB
        set server 192.168.10.50
        set cnid sAMAccountName
        set dn OU=Users,DC=lab,DC=local
        set type simple
        set username binduser
        set password BindPass123!
    next
end

🖱️ User & Authentication > LDAP Servers میں Create New پر جائیں۔User & Authentication > LDAP Servers mein Create New par jayen.Go to User & Authentication > LDAP Servers, Create New.

Step 5

دوسرے آپشن کے طور پر RADIUS سرور شامل کریں — VPN اور admin لاگ اِنز کے لیے عام۔ diagnose test authserver سے LDAP کنکشن ٹیسٹ کریں تاکہ غلطیاں جلدی پکڑی جائیں۔Doosre option ke taur par RADIUS server shamil karen — VPN aur admin logins ke liye aam. diagnose test authserver se LDAP connection test karen taake ghaltiyan jaldi pakri jayen.Add a RADIUS server as a second option — common for VPN and admin logins. Test the LDAP connection with diagnose test authserver so mistakes are found early.

config user radius
    edit RAD-LAB
        set server 192.168.10.51
        set secret RadiusSecret123!
        set auth-type auto
    next
end
diagnose test authserver ldap AD-LAB labuser LabUser123!

🖱️ User & Authentication > RADIUS Servers میں Create New پر جائیں۔User & Authentication > RADIUS Servers mein Create New par jayen.Go to User & Authentication > RADIUS Servers, Create New.

Step 6

SSO/FSSO سمجھیں: جب یوزر ونڈوز میں لاگ اِن کرتا ہے تو FSSO FortiGate کو بتاتا ہے کہ ہر IP کس یوزر کا ہے۔ پھر یوزرز دوسری لاگ اِن کے بغیر فائر وال پالیسیز سے گزر جاتے ہیں — یہی زیرو ٹرسٹ فرینڈلی طریقہ ہے۔SSO/FSSO samjhen: jab user Windows mein log in karta hai to FSSO FortiGate ko batata hai ke har IP kis user ka hai. Phir users doosri login ke baghair firewall policies se guzar jate hain — yahi Zero Trust friendly tareeqa hai.Understand SSO/FSSO: when a user logs into Windows, FSSO tells the FortiGate which user owns each IP. Users then pass through firewall policies without a second login — this is the Zero Trust friendly approach.

🖱️ User & Authentication > Single Sign-On میں سنگل سائن آن کے طریقے دیکھیں۔User & Authentication > Single Sign-On mein Single Sign-On ke tareeqe dekhen.See the Single Sign-On methods under User & Authentication > Single Sign-On.

تصدیقVerifyVerify

کیپٹو پورٹل سے labuser کے طور پر لاگ اِن کریں، پھر براؤز کریں۔ Forward Traffic لاگز میں سیشن پر صرف IP نہیں بلکہ یوزر نیم نظر آنا چاہیے۔Captive portal se labuser ke taur par log in karen, phir browse karen. Forward Traffic logs mein session par sirf IP nahi balke username nazar aana chahiye.Log in as labuser through the captive portal, then browse. Forward Traffic logs should show the username (not just the IP) on the session.

diagnose test authserver ldap AD-LAB labuser LabUser123!

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ LDAP ٹیسٹ فیل ہو گیا — 'bind failed' یا 'user not found'۔LDAP test fail ho gaya — 'bind failed' ya 'user not found'.LDAP test fails — 'bind failed' or 'user not found'.

✅ سرور IP، بائنڈ یوزر نیم/پاس ورڈ، dn سرچ بیس اور cnid چیک کریں۔ dn میں غلط OU سب سے عام وجہ ہوتی ہے۔Server IP, bind username/password, dn search base aur cnid check karen. dn mein ghalat OU sab se aam wajah hoti hai.Check the server IP, bind username/password, the dn search base, and cnid. A wrong OU in dn is the most common cause.

⚠️ پالیسی میں یوزر گروپ شامل ہے مگر یوزر اب بھی بلاک ہو رہا ہے۔Policy mein user group shamil hai magar user ab bhi block ho raha hai.User group added to policy but user still gets blocked.

✅ تصدیق کریں کہ یوزر پہلے آتھینٹی کیٹ ہوا (کیپٹو پورٹل یا FSSO) اور واقعی گروپ کا ممبر ہے۔ جو سیشن آتھینٹی کیٹ نہیں ہوتا وہ یوزر بیسڈ پالیسی سے کبھی میچ نہیں کرتا۔Tasdeeq karen ke user pehle authenticate hua (captive portal ya FSSO) aur waqai group ka member hai. Jo session authenticate nahi hota woh user-based policy se kabhi match nahi karta.Confirm the user authenticated first (captive portal or FSSO) and is actually a member of the group. An unauthenticated session never matches a user-based policy.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ FortiGate کو کیسے معلوم ہوتا ہے کہ کسی IP کے پیچھے کون سا یوزر ہے؟ (FSSO کانسیپٹ)FortiGate ko kaise maloom hota hai ke kisi IP ke peeche kaun sa user hai? (FSSO concept)How does FortiGate know which user is behind an IP address? (FSSO concept)

FSSO ونڈوز لاگ آنز سے یوزر لاگ اِن انفارمیشن جمع کرتا ہے (کلیکٹر ایجنٹ یا پولنگ سے) تاکہ FortiGate کو معلوم ہو کہ ہر IP کس یوزر کا ہے۔ پالیسیز پھر صرف IP کے بجائے یوزر گروپس پر بھی میچ کر سکتی ہیں۔FSSO Windows logons se user login information jama karta hai (collector agent ya polling se) taake FortiGate ko maloom ho ke har IP kis user ka hai. Policies phir sirf IP ke bajaye user groups par bhi match kar sakti hain.FSSO collects user login information from Windows logons (via a collector agent or polling) so the FortiGate knows which user owns each IP. Policies can then match user groups instead of just IP addresses.

❓ لوکل یوزرز کب استعمال کرتے ہیں اور LDAP یا RADIUS کب؟Local users kab istemal karte hain aur LDAP ya RADIUS kab?When do you use local users versus LDAP or RADIUS?

لوکل یوزرز FortiGate پر ہی رہتے ہیں — چھوٹی سیٹ اپس اور ٹیسٹنگ کے لیے ٹھیک ہیں۔ LDAP/RADIUS کمپنی کی موجودہ یوزر ڈائریکٹری استعمال کرتے ہیں، تو پاس ورڈ ایک جگہ تبدیل ہوتا ہے اور کئی ڈیوائسز آتھینٹیکیشن شیئر کر سکتے ہیں۔Local users FortiGate par hi rehte hain — choti setups aur testing ke liye theek hain. LDAP/RADIUS company ki mojooda user directory istemal karte hain, to password aik jagah tabdeel hota hai aur kai devices authentication share kar sakte hain.Local users live on the FortiGate itself — fine for small setups and testing. LDAP/RADIUS use the company's existing user directory, so passwords change in one place and many devices can share authentication.