Technical Tip: Fortinet's RADIUS Dictionary (VSA - vendor-specific attributes), NTRadPing
- August 18, 2009
- 0 replies
- 38405 views
Description
This article describes Fortinet's RADIUS Dictionary (VSA - vendor-specific attributes) added and modified to the extent that it could be used in NTRadPing, a RADIUS testing tool.
For more recent Fortinet's RADIUS Dictionary, check the link in 'Related Articles'.
The 'raddict.dat' file, in the attached ZIP package, provides the RADIUS VSA Dictionary for the NTRadPing tool only.
Scope
FortiGate.
Solution
Note: NTRadPing 1.5 refuses to start with a dictionary containing the types 'ether' and 'octets'.
For simplicity of use, those types are remapped to the 'string' type; therefore, those are not accurate to the original dictionary, but the tool will work.
Those attributes and the NTRadPing tool could be used and help in the tests described in the related topics linked below:
- Technical Tip: Authentication, Remote server group match of user group configuration with RADIUS server user, or Technical Tip: How FortiGate determines group memberships from RADIUS responses.
An example where Access-Accept received from the RADIUS server can affect a user's group membership and indirectly 'access rights' of the user in the network. - Technical Tip: Remote admin login with Radius selecting admin access account profile
Example where the 'wildcard' type of admin account is used for authentication (and possibly for authorization, therefore access profile assignment, or even accessible VDOM assignment and limitation).
The attached ZIP-ed 'raddict.dat' is the original name of the dictionary file used by NTRadPing.
To use it, back up the original 'raddict.dat' file in the NTRadPing directory, then place this modified 'raddict.dat' into the NTRadPing folder where the tool is run from.
Related article:
Technical Tip: Fortinet's RADIUS Dictionary and VSAs (latest)
