Skip to main content
Contributor III
November 7, 2008
Question

admins auth via radius (MS IAS)

  • November 7, 2008
  • 12 replies
  • 9962 views
Hi All, Did anyone managed to configure admin authorization from Radius server (MS IAS). I' ve got to a stage where Windows is showing that user has been authorized but FGT still doesn' t let me in. VSA in IAS is set like this: Vendor-Code: 12356 Vendor assigned attribute number: 1 Attribute format: String Value: prof_admin Debug in the CLI (diag deb appl fnbamd 255) is showing following: fnbamd_fsm.c[886] handle_req-Rcvd auth req 2883595 for adm in ADMINS_IAS opt=1 prot=8 fnbamd_radius.c[780] fnbamd_radius_auth_send-Sent radius req to 10.0.0.1: code=1 id=34 len=155 user=" adm" using MS-CHAPv2 fnbamd_auth.c[544] auth_tac_plus_start-Didn' t find tac_plus servers (0) fnbamd_auth.c[292] ldap_start-Didn' t find ldap servers (0) fnbamd_radius.c[980] fnbamd_radius_auth_validate_pkt-Invalid digest fnbamd_auth.c[1240] fnbamd_auth_handle_result-Error validating radius rsp fnbamd_fsm.c[1068] handle_auth_rsp-Error (5) for req 2883595 fnbamd_fsm.c[1134] handle_auth_timeout_with_retry-Session timeout, retry fnbamd_auth.c[205] radius_start-Didn' t find radius servers (0) fnbamd_fsm.c[1145] handle_auth_timeout_with_retry-retry failed fnbamd_fsm.c[1177] handle_auth_timeout_without_retry-Session expired fnbamd_comm.c[104] fnbamd_comm_send_result-Sending result 3 for req 2883595 IAS is showing that user has been granted access. My assumption is that either FGT doesn' t like self-signed cert for MS-CHAPv2 on the radius or the parameters inside IAS are wrong. Please help. Marko

    12 replies

    abelio
    SuperUser
    SuperUser
    November 7, 2008
    Did you test manually radius authentication from the FGT against your server? Another point: default auth type is ' auto' and ' PAP' is the first type attempted; ' auto' uses PAP, MSCHAP_v2, and CHAP in that order Could you post the output of CLI command: " show full user radius" ?
    Contributor III
    November 7, 2008
    manual radius test: GATEKEEPER # diagnose test authserver radius slemish_ias mschap2 adm Password authenticate ' adm' against ' mschap2' failed(no response), assigned_rad_session_id=46989312 session_timeout=0 secs! Auth is set to MSCHAP2 otherwise IAS doesn' t authorize the user (I' ve tried PAP, CHAP, MSCHAP, MSCHAP2) GATEKEEPER # show full user radius config user radius edit " slemish_ias" set all-usergroup disable set auth-type ms_chap_v2 set nas-ip 0.0.0.0 set radius-port 0 set secret ENC wDxrew/rh0jJUGMLyR76XasKJMRUS6IcT/9UMo9Yc4+j4a9W0Vb7/TRqUMS9jMW3iV/EKMBESMfUUtsfSIaWWpfsAI4CT15vO3Aoacz5LNt/E8ID set server " 10.0.0.1" set use-group-for-profile disable set use-management-vdom disable set secondary-secret ENC O422NLZh5WBJn7c9Xk7M87YEwTERLzIt0T9bWSkswluTN/h1VLmgzGh791fTEvq2Xv1X974r+Pz52ffC9g5xGG+KMUl6+luzZIcl+1NnfRQwvYo9 set secondary-server ' ' next end Output from Event Viewer: User adm was granted access. Fully-Qualified-User-Name = DOMAIN\adm NAS-IP-Address = <not present> NAS-Identifier = GATEKEEPER Client-Friendly-Name = FortiGate300A Client-IP-Address = 10.0.0.2 Calling-Station-Identifier = <not present> NAS-Port-Type = <not present> NAS-Port = <not present> Proxy-Policy-Name = Use Windows authentication for all users Authentication-Provider = Windows Authentication-Server = <undetermined> Policy-Name = fortigate_access Authentication-Type = MS-CHAPv2 EAP-Type = <undetermined> Any ideas? -- Marko
    abelio
    SuperUser
    SuperUser
    November 7, 2008
    ORIGINAL: marko manual radius test: GATEKEEPER # diagnose test authserver radius slemish_ias mschap2 adm Password authenticate ' adm' against ' mschap2' failed(no response), assigned_rad_session_id=46989312 session_timeout=0 secs! Auth is set to MSCHAP2 otherwise IAS doesn' t authorize the user (I' ve tried PAP, CHAP, MSCHAP, MSCHAP2)
    Ok, stop here a moment; for some reason there' s no communication (no response error message) between the Fortigate and the radius server; First the basics things: - which AA ports is talking your radius server? 1645/1646 or 1812/1813 ? If you want to know which port uses your FTGate radius client, look for " radius-port" line within the output of " show system global" CLI command. - re-check secrets in both sides once again and re-try hope it helps,
    40net
    New Member
    November 24, 2008
    Hey Marko Did you find any solution to that ? I am having the same issue ...
    iFortify
    New Member
    January 17, 2009
    For information on configuring administrative access with Radius Authentication, please refer to the MR7 Administration Guide starting on page 198
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!