Skip to main content
rbraha
Staff
Staff
August 19, 2022

Technical Tip: Login as administrator on FortiAuthenticator from an external radius server

  • August 19, 2022
  • 0 replies
  • 628 views

Description

 

This article describe how to can login in FortiAuthenticator as an administrator from an external radius server.

 

Scope

 

FortiAuthenticator

 

Solution

 

In this article two FortiAuthenticator are used, one is Radius client and the second is a Radius server.

 

On the second FortiAuthenticator configured as Radius server, the first FortiAuthenticator is added as Radius client and also added in the radius policy.

 

    client rad,server.png

 

rad policy 1.png

 

Other tabs on the radius policy remains the same, only in identity source one can specify realm and user group that has been created before for users imported from AD side.

 

identity source.png

 

To import LDAP user from AD and creating realm on FortiAuthenticator, follow this below KB articles . The remote users can have token for 2FA authentication .

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-import-remote-LDAP-user-in/ta-p/191505

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-FortiAuthenticator-realm-based-authentication/ta-p/189637

 

users.png

 

On the first FortiAuthenticator , create new radius under Authentication - > Remote Auth. Servers - > Radius - >Create 

 

client1.png

 

Under User Management - > Remote Users select Radius - > Create New 

 

Create the new user as administrator and give full access permissions  with the same username as the user imported from the second FortiAuthenticator as Radius server .

 

user1.png

 

Create an user group and add this user in this group 

 

user 2.png

 

Create realm here, with same name as domain and as user source select Radius server.

 

realm2.png

 

Go to System Access - > Administration  and the section Realm, select the realm and the group that was created before.

 

system access png.png

 

Test by logging in using the username: gatuzo and the login was successful.

 

user loginpng.png

 

From the second FortiAuthenticator as radius server check the radius debug logs.

 

debug logspng.png

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.