MISMIS Lv3Posted 29 May 2023 14:49
  
see the internet access policy: Examine the current firewall policies to see which one is in charge of permitting internet access. This policy may include provisions for access to popular websites such as YouTube and Facebook.
Naomi Lv3Posted 29 May 2023 14:45
  
To access the Sangfor NGAF administration interface, launch a web browser and input the IP address or hostname of your NGAF device.
Rejie08455 Lv1Posted 29 May 2023 14:45
  
The users can access the internet without authentication because the policy for new users is set to "No authentication." To block access for these specific test users, you need to configure access control rules on Sangfor NGAF to deny internet access for their IP addresses.
Zonger Lv4Posted 29 May 2023 14:41
  
If you have integrated Active Directory (AD) users with your Sangfor NGAF (Next-Generation Application Firewall) and you want to block internet access for new users until they sign on, you may need to adjust your firewall policies. Here are the steps you can follow:

Access the Sangfor NGAF management interface: Open a web browser and enter the IP address or hostname of your NGAF device to access the management interface.

Navigate to Firewall Policy settings: Look for the Firewall Policy section or similar in the NGAF management interface. This is where you can configure rules to control internet access.

Identify the policy for internet access: Review the existing firewall policies to identify the one responsible for allowing internet access. This policy might have rules allowing access to popular websites like YouTube and Facebook.

Modify the policy to include authentication: Edit the policy that allows internet access and add an authentication requirement to it. This ensures that users must sign in before being allowed internet access.

Specify the AD authentication requirement: Within the policy settings, configure the authentication method to use Active Directory. This ensures that users must authenticate against AD before being granted internet access.

Apply the policy to the test user group: Specify the group or users (in this case, the three test users) who should be subject to the authentication requirement. This will restrict internet access for new users until they sign in successfully.

Test and verify: Test the new configuration by opening a new tab on the browser without signing in as one of the test users. Verify that access to websites like YouTube and Facebook is blocked until authentication is completed.
RegiBoy Lv5Posted 29 May 2023 14:41
  
Specify the group or users (in this case, the three test users) who should be subject to the authentication requirement. This will restrict internet access for new users until they sign in successfully.
ArsalanAli Lv3Posted 26 May 2023 12:59
  
I have put the Check on "NO Authentication for New User"  and issue resolve
now only authenticated users can use the Internet
ArsalanAli Lv3Posted 26 May 2023 12:56
  
I have put check on "No-Authentication for new User" and issue resolved now

image_2023-05-26_095500334.png (19.06 KB, Downloads: 373)

image_2023-05-26_095500334.png
MTR Lv2Posted 24 May 2023 01:26
  
If you have integrated Active Directory (AD) users with your Sangfor NGAF (Next-Generation Application Firewall) and you want to block internet access for new users until they sign on, you may need to adjust your firewall policies. Here are the steps you can follow:

Access the Sangfor NGAF management interface: Open a web browser and enter the IP address or hostname of your NGAF device to access the management interface.

Navigate to Firewall Policy settings: Look for the Firewall Policy section or similar in the NGAF management interface. This is where you can configure rules to control internet access.

Identify the policy for internet access: Review the existing firewall policies to identify the one responsible for allowing internet access. This policy might have rules allowing access to popular websites like YouTube and Facebook.

Modify the policy to include authentication: Edit the policy that allows internet access and add an authentication requirement to it. This ensures that users must sign in before being allowed internet access.

Specify the AD authentication requirement: Within the policy settings, configure the authentication method to use Active Directory. This ensures that users must authenticate against AD before being granted internet access.

Apply the policy to the test user group: Specify the group or users (in this case, the three test users) who should be subject to the authentication requirement. This will restrict internet access for new users until they sign in successfully.

Test and verify: Test the new configuration by opening a new tab on the browser without signing in as one of the test users. Verify that access to websites like YouTube and Facebook is blocked until authentication is completed.
Faisal Piliang Posted 23 May 2023 19:26
  
Hi,

If you encounter this error after setting up SSO using profiles, it's likely that your IdP is incorrectly assuming that you're using the SSO profile for your organization. If so, your IdP SSO profile settings may be usable only if you use them to configure the SSO profile for your organization.

Thanks
ArsalanAli Lv3Posted 23 May 2023 15:34
  
I have implemented a policy that user IP can not go on internet and when it sign on to its user account can go to internet .... Screenshot is attached

After this policy User internet is block, but there is no option of signon (means SSO screen is not showing)

image_2023-05-23_123416164.png (14.57 KB, Downloads: 368)

image_2023-05-23_123416164.png

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
1
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders