Skip to main content
smujeeb
Staff
Staff
July 29, 2022

Technical Tip: FortiAuthenticator Tacacs+ troubleshooting and debugs

  • July 29, 2022
  • 0 replies
  • 1341 views
Description

This article describes how to get debugs for Tacacs+ authentication on FortiAuthenticator appliance.

Scope

FortiAuthenticator.

Solution

In the FortiAuthenticator Tacacs debugs, the configured realm is not shown instead it refers to readiusRealm.

This causes confusion whether the realm configuration has been honoured during an authentication request.

 

smujeeb_0-1659071569704.jpeg


The above screenshot shows realmtest as the configured realm on the Tacacs Policy.

 

 In the Tacacs debugs however, the realm is shown as radiusRealm.

 

smujeeb_1-1659071569730.jpeg

 

This result may cause some concern whether the correct real has been matched by FortiAuthenticator’s Tacacs Policy.

The realm can be verified if explicitly mentioned in the user login using the Tacacs Authentication debugs along with authentication method.

 

smujeeb_2-1659071569736.jpeg

 

In order to get more details, use the Radius Authentication debug in the debugs section.

 

smujeeb_3-1659071569752.jpeg

 

In the above debugs it shows that a realm was not specified and realm ID: 1 is used as default.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!