Skip to main content
Houl
New Member
December 27, 2021
Solved

Is it possible to raise the priority of RADIUS authentication in SSL VPN authentication rules?

  • December 27, 2021
  • 9 replies
  • 7957 views

Good day.

 

I'm struggling with next problem

 

We are using SSL VPN connection with two auth services LDAP and RADIUS (2FA thought FortiAuthenticator).

And we were surprised that FortiGate sends auth queries (according to authentication rules in SSL VPN configuration) simultaneously. It's f***** ridiculous.

My bosses cardinally against of using realms. They demand to use single URL.

Yes usually we don't have problems because use individual groups.

But we have several groups which must use 2FA but, if FAC will lay down, they have to use LDAP.

And without realms it's impossible to do auth rules configuration for these groups.

Is it possible to delimit users (without and with 2FA) with using single URL and without realms?

 

For example:

config authentication-rule
edit 1
set groups "User_Group_1_2FA"
set portal "User_Group_1"
set auth radius
next
edit 2
set groups "User_Group_2"
set portal "User_Group_2"

set auth ldap
next
edit 3

set groups "User_Group_1"
set portal "User_Group_1"
set auth ldap
next

end

 

Best answer by Debbie_FTNT

I wrote a KB detailling how FortiGate goes about SSLVPN authentication: https://community.fortinet.com/t5/FortiGate/Technical-Tip-A-quick-guide-to-FortiGate-SSLVPN-authentication/ta-p/202041

hope this answers any questions you might have :)

9 replies

Toshi_Esumi
SuperUser
SuperUser
December 27, 2021

How about separating policies and put the one with RADIUS/User_Group_1_2FA at the top?

 

Toshi

Houl
HoulAuthor
New Member
December 27, 2021

This doesn't work.

 

At first step SSL VPN deamon gets all groups from default realm and policies.

At second it sends simultaneously query to all auth services which were found in default realm auth rule.

After it uses the first answer from auth services. So... in this situation RADIUS will be always the last one.

 

Debbie_FTNT
Staff & Editor
Staff & Editor
December 28, 2021

Hey Houl,

I'm sorry to say that without realms to force authentication against specific groups, FortiGate will send the authentication request to all possible authentication servers based on SSLVPN policies as you have outlined above.
The intention behind it is to keep login latency low; if FortiGate checks one server after the other it would have to wait for failure/timeout each time and depending on setup, this could cause login wait times to quickly become ridiculous.
I agree that in cases such as yours the FortiGate design has limitations, but at present the only workaround FortiGate offers is using SSLVPN realms to ensure the user is only authenticated against very specific groups (and thus very specific authentication servers) instead of all.
Other than that, a feature request to allow designation of preferred authentication server or backup-only authentication servers might be an option, but feature requests need to be submitted via Fortinet Sales, that's not something I can do, my apologies.

Sorry for the bad news :(

Toshi_Esumi
SuperUser
SuperUser
December 27, 2021

Really? I need to test it myself then.

Debbie_FTNT
Staff & Editor
Staff & Editor
December 28, 2021

I wrote a KB detailling how FortiGate goes about SSLVPN authentication: https://community.fortinet.com/t5/FortiGate/Technical-Tip-A-quick-guide-to-FortiGate-SSLVPN-authentication/ta-p/202041

hope this answers any questions you might have :)

Houl
HoulAuthor
New Member
December 28, 2021

Thanks for full description!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!