Skip to main content
cysaw
Staff & Editor
Staff & Editor
July 3, 2026

Technical Tip: How to configure RADIUS over TLS for admin access in the FortiNDR with the FortiAuthenticator as Radius Server

  • July 3, 2026
  • 0 replies
  • 20 views

Description

This article describes how to configure RADIUS over TLS for admin access in the FortiNDR with the FortiAuthenticator as Radius Server.

Scope

FortiNDR.

Solution

Configuration in FortiNDR:

  1. Generate a CSR (Certificate Signing Request) at System -> Certificate -> Generate in the FortiNDR.

    482d4bfb.png


  1. Sign the FortiNDR 'CSR', in this case, follow the guide below to sign the CSR in FortiAuthenticator:
    Technical Tip: How to sign a CSR on FortiAuthenticator

  1. Export the signed certificate and 'CA' certificate from the FortiAuthenticator and import it into the FortiNDR.

  2. Configure a new Radius Server at User & Authentication -> RADIUS Server as seen in the screenshot below:

    ca93950a.png


  3. Configure a new Radius Administrator as seen in the screenshot below in System -> Administrators:

    ab0266f2.png


Configuration in FortiAuthenticator:

  1. Enable the highlighted services as seen in the screenshot below:

    ffc9c75a.png


  2.  Go to RADIUS Service -> Clients -> Create New, by following the screenshot below:

    f2efb29f.png


  3. Go to User Management > Local Users > Create New, by following the screenshot below:

    5c267a89.png



    1. Go to User Management -> User Group >- Create New, by following the screenshot below:

      8698f443.png


    2. Go to RADIUS Service -> Policies -> Create New, by following the screenshots below:


      97d9f9e7.png


      44ce9b4b.png


      66c334e0.png



  1. Login to the FortiNDR over the RADIUS over TLS using the radius admin to check if the account setup is successful.

    9fd3c805.png