Fortiswitch RADIUS Authentication not arrives external RADIUS Server
Hello all,
I am currently setting up 802.x1 EAP-TLS authentication on an external cloud radius server on my FortiSwitch 448E-POE (Fortilink) and am experiencing a minor issue.
Basically, I wanted to do this via TLS TCP (RadSec).
I noticed that the FortiSwitches only send the packets as UDP. Presumably, the current FortiSwitch FW S448EP-v7.6.2-build1085,250526 (GA) does not support TLS over TCP, is that correct? In any case, there is no mention of “set transport-protocol tls” in the radius profile on the switch.
The FGT with FW v7.6.3 build3510 (feature) seems to support this; at least, I can see that the packets are sent as TCP and they also arrive on my RADIUS server.
In any case, I have now adjusted the RADIUS client so that it performs authentication via UDP on the RADIUS server. The query is also successful and arrives at the RADIUS server.
The problem is that when I try to authenticate on a port of the FortiSwitch, no packets arrive at the RADIUS server. In debug mode, I can see that packets are leaving switch 10.255.1.2, but nothing is arriving at the Radius server.
I have also created a firewall policy for testing: incoming interface fortilink_default / outgoing WAN / source all / destination all / service all
Regards
fabss
