User
Monitor
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
591
•
Figure 393: Authentication Settings
Monitor
You can go to
User > Monitor
to view lists of currently authenticated users, active SSL
VPN sessions, activity on VPN IPSec tunnels, authenticated IM users, and banned users.
For each authenticated user, the list includes the user name, user group, how long the
user has been authenticated (
Duration
), how long until the user’s session times out (
Time
left
), and the method of authentication used. VPN tunnel information includes user name,
IP address of the remote client, connection type (IPSec), Proxy ID source/destination
(IPSec), and start time of the sessions (SSL). The list of IM users includes the source IP
address, protocol, and last time the protocol was used. The Banned User list includes
users configured by administrators in addition to those quarantined based on AV, IPS, or
DLP rules.
The following lists are available:
•
•
•
•
•
NAC quarantine and the Banned User list
Firewall user monitor list
In some environments, it is useful to determine which users are authenticated by the
FortiGate unit and allow the system administrator to de-authenticate (stop current session)
users. With the Firewall monitor, you can de-authenticate all currently authenticated users,
or select single users to de-authenticate. To permanently stop a user from re-
authenticating, change the FortiGate configuration (disable a user account) and then use
the User monitor to immediately end the user’s current session.
To view the list of authenticated users (Firewall), go to
User > Monitor > Firewall
.
Authentication Timeout
Enter a length of time in minutes, from 1 to 480. Authentication
Timeout controls how long an authenticated firewall connection can be
idle before the user must authenticate again. The default value is 30
Protocol Support
Select the protocols to challenge during firewall user authentication.
Certificate
If using HTTPS protocol support, select the Local certificate to use for
authentication. Available only if HTTPS protocol support is selected.
Apply
Apply selections for user Authentication Settings.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...