MTR Lv2Posted 24 May 2023 01:26
  
If you have integrated Active Directory (AD) users with your Sangfor NGAF (Next-Generation Application Firewall) and you want to block internet access for new users until they sign on, you may need to adjust your firewall policies. Here are the steps you can follow:

Access the Sangfor NGAF management interface: Open a web browser and enter the IP address or hostname of your NGAF device to access the management interface.

Navigate to Firewall Policy settings: Look for the Firewall Policy section or similar in the NGAF management interface. This is where you can configure rules to control internet access.

Identify the policy for internet access: Review the existing firewall policies to identify the one responsible for allowing internet access. This policy might have rules allowing access to popular websites like YouTube and Facebook.

Modify the policy to include authentication: Edit the policy that allows internet access and add an authentication requirement to it. This ensures that users must sign in before being allowed internet access.

Specify the AD authentication requirement: Within the policy settings, configure the authentication method to use Active Directory. This ensures that users must authenticate against AD before being granted internet access.

Apply the policy to the test user group: Specify the group or users (in this case, the three test users) who should be subject to the authentication requirement. This will restrict internet access for new users until they sign in successfully.

Test and verify: Test the new configuration by opening a new tab on the browser without signing in as one of the test users. Verify that access to websites like YouTube and Facebook is blocked until authentication is completed.

I Can Help:

Change

Moderator on This Board

1
131
3

Started Topics

Followers

Follow

18
8
0

Started Topics

Followers

Follow

Board Leaders