New Member
October 23, 2019
Question
FMG 5.6 Authentication with RADIUS (Cisco ISE) users
- October 23, 2019
- 1 reply
- 5594 views
Hello
When configuring FortiManager with Cisco ISE RADIUS Server, FMG don't attribute the good profile to the user as asked by ISE.
You find below my configuration:
On ISE side:
[ol]on FMG side:
[ol]The problem is when I connect on the FMG with a user member of GROUP-RO, ISE send the necessary attributed of the Access Profile with PROFILE_RO, but the FMG consider the user as member of another profile as described below.
# diagnose system admin-session list
*** entry 7 *** session_id: 12427 (seq: 0) username: user_ro admin template: GROUP-RW from: GUI(1.1.1.1) (type 1) profile: SUPERUSER (type 1) adom: root session length: 559 (seconds)
idle: 301 (seconds)
Anyone has any idea how to resolve this issue?
Thank you for your help!
