Skip to main content
FortiKoala
Staff
Staff
October 1, 2018

Technical Note: Using VIP (Virtual IP) Does Not Work for RADIUS

  • October 1, 2018
  • 0 replies
  • 1028 views
Description
Controller rejecting authentication response from the appliance in L2 High Availability configuration.  Controller's AAA Server configuration contains Network Sentry's VIP (Virtual IP).

The appliance responds to RADIUS requests using the physical eth0 IP address (regardless of High Availability configuration).  The controller will not accept a response from an IP address that is not defined in the AAA Server configuration.

Scope
Version:  8, 9

Solution
The following must be configured on the controller:
  • 2 AAA Server configurations: one for the Primary Control Server IP and one for the Secondary Control Server IP.
  • Fail over to Secondary when Primary does not respond (Round Robin cannot be used).
Refer to the appropriate integration guide for more details regarding configuration.




Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.