Forticlient Radius Authentication Across IPSEC Tunnel
Currently, I manage small pools of locally configured building engineer accounts on several remote sites (all fortigate) that hub&spoke topology back to our main site. They use forticlient to connect to their local FG network to manage what they need to manage. My boss wants us to move this authentication from me managing local accounts to them authenticating with their AD credentials to our radius server back at the main site. Currently, when clients connect with FC to our main site they use radius auth (MS NPS).
I've configured radius authentication on one of the remote FGs
edit "RADIUS-01"
set server "x.x.x.x" (server IP)
set secret ENC 32HGInwGoQ0aUnuzGS6FrcSgyB8on8I1Ugyfwm/SeNjKfLNQSbePRS29upRikZo3m34eh3qW5o3E8085RlmzYMu45eCCw9KADJoEdvQkpn5iX2sQS8PKze9rOiKPJ5z6RDR61o7Q9WzC7kxKH9CeOwhxTOj3sWwH0kl/JM/hJnoxPF4gHZD0J5TMOX7ZJVQ9IcF/rA==
set timeout 30
set auth-type pap
set source-ip "x.x.x.x" (local interface gw of subnet allowed to talk across the tunnel)
set interface-select-method specify
set interface "CORP" (tunnel interface back to main site)
I've tested ping and traceroute sourcing from the local interface and get positive responses so the traffic is allowed across the tunnel from that interface, but I am still getting "Can't contact RADIUS server"
Looking for any guidance.
