Question
admins auth via radius (MS IAS)
Hi All, Did anyone managed to configure admin authorization from Radius server (MS IAS). I' ve got to a stage where Windows is showing that user has been authorized but FGT still doesn' t let me in. VSA in IAS is set like this: Vendor-Code: 12356 Vendor assigned attribute number: 1 Attribute format: String Value: prof_admin Debug in the CLI (diag deb appl fnbamd 255) is showing following: fnbamd_fsm.c[886] handle_req-Rcvd auth req 2883595 for adm in ADMINS_IAS opt=1 prot=8 fnbamd_radius.c[780] fnbamd_radius_auth_send-Sent radius req to 10.0.0.1: code=1 id=34 len=155 user=" adm" using MS-CHAPv2 fnbamd_auth.c[544] auth_tac_plus_start-Didn' t find tac_plus servers (0) fnbamd_auth.c[292] ldap_start-Didn' t find ldap servers (0) fnbamd_radius.c[980] fnbamd_radius_auth_validate_pkt-Invalid digest fnbamd_auth.c[1240] fnbamd_auth_handle_result-Error validating radius rsp fnbamd_fsm.c[1068] handle_auth_rsp-Error (5) for req 2883595 fnbamd_fsm.c[1134] handle_auth_timeout_with_retry-Session timeout, retry fnbamd_auth.c[205] radius_start-Didn' t find radius servers (0) fnbamd_fsm.c[1145] handle_auth_timeout_with_retry-retry failed fnbamd_fsm.c[1177] handle_auth_timeout_without_retry-Session expired fnbamd_comm.c[104] fnbamd_comm_send_result-Sending result 3 for req 2883595 IAS is showing that user has been granted access. My assumption is that either FGT doesn' t like self-signed cert for MS-CHAPv2 on the radius or the parameters inside IAS are wrong. Please help. Marko
