Skip to main content
Lessue
Visitor III
December 1, 2021
Solved

Authenticating SSL VPN with RADIUS using class 25 possible?

  • December 1, 2021
  • 3 replies
  • 3620 views

With AnyConnect it is possible to authenticate to RADIUS and let NPS handle which group-policy/tunnel-group the user should receive based on their rights in NPS. Is this possible with Fortigate SSL-VPN and is there anything special needed to configure this besides the NPS itself?

 

I can't seem to find any documentation about this type of implementation.

Best answer by xsilver_FTNT

Hello,

it is possible to pair users to specific user group defined on FortiGate.

This pairing is for authentication done strictly through Fortinet-Group-Name VSA (vendor specific attribute) AVP (additional value pair).
Using anything else, like Class AVP, is not possible for active authentications.

 

More details about RADIUS Group Match, as the feature is usually called on FortiOS/FortiGate, kindly refer to this KB:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Authentication-Remote-server-group-match-of-user/ta-p/190905?externalID=FD36464

 

3 replies

xsilver_FTNT
Staff
Staff
December 1, 2021

Hello,

it is possible to pair users to specific user group defined on FortiGate.

This pairing is for authentication done strictly through Fortinet-Group-Name VSA (vendor specific attribute) AVP (additional value pair).
Using anything else, like Class AVP, is not possible for active authentications.

 

More details about RADIUS Group Match, as the feature is usually called on FortiOS/FortiGate, kindly refer to this KB:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Authentication-Remote-server-group-match-of-user/ta-p/190905?externalID=FD36464

 

Lessue
LessueAuthor
Visitor III
December 2, 2021

Thank you. Another good link I found for matching the group is below.

 

Technical Tip: How to define group based authoriza... - Fortinet Community

xsilver_FTNT
Staff
Staff
December 2, 2021

Yes, good one as well, more oriented to NPS while my one was more on how FGT handles that and what is expected in RADIUS Access-Accept to make it working.
Both are good sources.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!