Skip to main content
shane_caznet
New Member
January 16, 2018
Question

IPv6 users not authenticated by RSSO and FSSO

  • January 16, 2018
  • 6 replies
  • 10744 views

Hi

 

We have 2 Fortigate 300D running FortiOS 5.4.7 in a HA A-A cluster.

 

Our users are authenticated to our Fortigates by 2 ways: 1) FSSO using the Active Directory collector agent for domain joined machines, and 2) RSSO using Radius Accounting from our wireless (Ubiquiti) to Microsoft NPS Radius for non-domain joined BYOD devices such as iPads.

 

Our users show as authenticated with IPv4 sessions (user to IP address) as expected for both authentication types. However, we do not see any authenticated users with IPv6 addresses. When users access the internet using an IPv6 address, they get our unauthenticated user policy.

 

I'm not sure what I need to change to get both the IPv4 and IPv6 authentication for every user. Does Fortigate support dual-stack for user auth in this scenario? Am I missing something?

 

Shane

    6 replies

    xsilver_FTNT
    Staff
    Staff
    January 16, 2018

    Hi Shane,

     

    there is no GA release supporting IPv6 in FSSO as of now.

    See "FSSO does not currently support IPv6." in FortiOS Release Notes page 14 'Fortinet Single Sign-On' section in integration support part.

    https://docs.fortinet.com/uploaded/files/4088/fortios-v5.6.3-release-notes.pdf

     

    There is IPv6 support in RADIUS Accounting (RSSO) on FortiOS.

    If you send Framed-IPv6-Address then FortiGate will process it.

    Example:

    ----------

    # sent data via radclient (Freradius-utils)

    root@SRV-DEB-1:~# echo "Acct-Status-Type = Start, User-Name = JohnDoe , Class = ClassProfile , Framed-IPv6-Address = 2001:db8:0:69a1::1" | radclient -4 -c 1 -n 1 -x 192.168.32.251:1813 acct fortinet Sending Accounting-Request of id 19 to 192.168.32.251 port 1813 Acct-Status-Type = Start User-Name = "JohnDoe" Class = 0x436c61737350726f66696c65 Framed-IPv6-Address = 2001:db8:0:69a1::1

    # result in debug app radiusd -1

    FGVM_251 # Received radius accounting eventvd 0:root Add/Update auth logon for IP 2001:db8:0:69a1::1 for user (null) DB 0 insert [ep='n/a' pg='ClassProfile' ip='2001:db8:0:69a1::1'] success

    # result in DB

    FGVM_251 # diagnose test application radiusd 33 RADIUS server database [vd root]: "index","start time","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile" 1,1516088594,07:59:37,"2001:db8:0:69a1::1","","n/a","n/a","<default profile>",0,Yes Best regards,

    Tomas

    sviusa
    New Member
    August 9, 2018

    Hello,

     

    I'm in the same config as yours. trying to make the same exact thing. for now no way.

    I've tried to make the machine IPv6 only and the log on fortigate shows :

     

    RADIUS server database [vd root]: "index","start time","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile" 1,1533749461,00:00:00,"::/32""LABUSER1","allow","no log","A12-RUN+]L",1,No 2,1533805132,00:00:00,"192.168.10.166""LABUSER2","allow","no log","A12-RUN+]�",1,No

     

    Seams that the AP is not forwarding the framed-IPv6-Address...

     

    is there any other means to achieve this ? maybe using Forticlient ?

     

    thanks,

     

    Regards,

     

     

    Jeff_FTNT
    Staff
    Staff
    August 9, 2018

    FOS 6.0 support ipv6 FSSO.

     

    IPv6 support for FSSO (1) connecting FSSO agent over IPv6; (2) accepting and applying IPv6 FSSO logons for IPv6 firewall policies.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!