Technical Tip: How to configure Radius over TLS (RADSEC) using FortiAuthenticator as Radius Server
| Description | This article describes how to configure Radius over TLS (RADSEC) using FortiAuthenticator as Radius server. | ||||||||||||
| Scope | FortiManager/FortiAnalyzer v7.4.6, v7.6.2 and above. | ||||||||||||
| Solution | FortiAuthenticator:
'lfac_root_ca' (FortiAuthenticator Local CA) is used to sign the 'radius_cert_fqdn' certificate.
FortiManager:
Wildcard users will be used as an example:
Test Scenario: Go to FortiManager/FortiAnalyzer GUI and log in with the Radius user.
Troubleshooting guide:
diagnose debug application auth 255 diagnose debug timestamp enable diagnose debug enable
Sample output:
FMG # diag debug application auth 255
diagnose debug reset |











