Skip to main content
Nick_Mavrou
New Member
October 24, 2022
Question

Fortigate and Cisco ISE User based policy

  • October 24, 2022
  • 1 reply
  • 9680 views

Hi Guys,

 

I have an implantation which requires the fortigate to recognize a user when it is connecting to WiFi over dot1x. The radius server is Cisco ISE and the external ID I am using is an MS Active Directory. The whole communication between the client and the Cisco ISE happens over certificates, so all good here. Is it any way the fortigate to be able to see that and then perform a firewall policy based on user?

 

Many Thanks 

1 reply

distillednetwork
Explorer II
October 24, 2022

You could look at sending Radius accounting messages from the ISE server to the fortigate using RSSO.  When enabled, you will be able to send radius attributes based on user details in ISE and match them to a group in Fortigate.

 

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/85730/radius-single-sign-on-rsso-agent

 

If you have a large number of users connecting to the wifi, I would suggest using an FSSO server and send the radius messages to that instead of the fortigate direct.  This will greatly reduce the load on the Fortigate.  This article will show at the bottom how you can enable Radius accouting in the FSSO agent and then link the fortigate to the FSSO server to get the details:

 

https://community.fortinet.com/t5/Fortinet-Forum/Fortigate-Combining-RSSO-and-FSSO/m-p/219887

 

Hope that helps!

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!