Catch-all RADIUS client?
Running FAC 5.4.1 in HA.
We have several different RADIUS clients defined on our FAC. Mostly for VPN systems. Different systems use different realms, or are not sourced from contiguous IP space.
I would like to have our FortiGate administrator access controlled by FAC. However they all come from various IP space, and defining a RADIUS client for each one is not feasible.
I tried to define a new RADIUS client using client source IP of 0.0.0.0 and defined a matching RADIUS client attribute. However, what I observed is that the FAC matched this entry first, instead of matching the more specific RADIUS client entries with specific source IPs defined. Even after removing that entry, the matching still occurred as shown in the RADIUS debug logs. I had to reboot the FAC to get VPN authentication working again.
Is there a way to define a catch-all RADIUS client entry that is only used if a more specific entry does not match? Or a way to sort RADIUS client profiles to force which ones the FAC evaluates first?
