Hi all,

I'm studying an implementation where PF will be the centralized NAC of many 
sites made of many people from different groups. So a single site can have 
different groups defined, I was thinking on using PF to release VLAN based on 
the Active Directory Group the person is part of. Then I need to put each group 
on a firewall rule on my centralized Fortigate FW to give them access to 
network resources. The main problem is that some people could be part of 
different groups because they need access to different network resources. Is 
there a way to accomplish this? I was thinking of firewall sso but how does it 
work? Is there a way to apply firewall rules to the single user based on PF 
rules?


Thank you in advance


Luca
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to