Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.95
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Fortigate Parameter Explanation and Conversion Suggestions")}}

Fortigate Parameter Explanation and Conversion Suggestions

{{ $t('productDocDetail.updateTime') }}: 2026-01-04

FortiGate Parameter

FortiGate Parameter Description

Corresponding Sangfor NGAF Module/Parameter

Migration Notes

set server

LDAP/AD server address

Policies > Authentication > External Auth Server > LDAP Server

Directly corresponds; IP can remain the same

set cnid

User login attribute (e.g., sAMAccountName)

Policies > Authentication > External Auth Server > LDAP Server > User Attributes

Usually set as sAMAccountName

set dn

Base DN for queries, defines LDAP search scope

Policies > Authentication > External Auth Server > LDAP Server > Base DN

Fill in according to the original configuration

set type

LDAP type (regular means standard AD)

Policies > Authentication > External Auth Server > LDAP Server

Default

set username

LDAP bind account for querying users

Policies > Authentication > External Auth Server > LDAP Server > Admin DN

Enter the full domain account, e.g., user@domain.com

set password

Bind account password (encrypted)

Policies > Authentication > External Auth Server > LDAP Server > Password

Must re-enter; encrypted passwords cannot be imported

set group-member-check

Check user group membership

User Group Mapping (LDAP Group Mapping)

Not Support

set secure

Enable LDAPS encryption

Policies > Authentication > External Auth Server > LDAP Server

Not Support

set port

LDAP service port

Policies > Authentication > External Auth Server > LDAP Server Port

389

set authtimeout

User authentication timeout (seconds)

Policies > Authentication > External Auth Server > LDAP Server > Timeout

Default 5 seconds; can keep the same