Skip to main content
braddavisgwh
New Member
November 21, 2025
Solved

NAT Query on fortiauthenticator cloud - radius

  • November 21, 2025
  • 6 replies
  • 625 views
 

Hi all,

 

In the process of setting up FAC Cloud with radsec and a fortigate firewall - we are seeing the traffic coming to the FAC from a different IP to what is our FWs public IP address - when setting our radius client, this took me a little while to find. 

 

Can anyone advise what should be set under the client IP for radius, or how the traffic is handled please?

 

Best answer by AEK

Hi Brad

When configuring the RADIUS client in FAC, the client IP should be the source IP, i.e. the public IP used by the device as source when sending the RADIUS request.

6 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
November 24, 2025

Hello braddavisgwh, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
November 25, 2025

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Jean-Philippe - Fortinet Community Team
AEK
SuperUser
AEKAnswer
SuperUser
November 25, 2025

Hi Brad

When configuring the RADIUS client in FAC, the client IP should be the source IP, i.e. the public IP used by the device as source when sending the RADIUS request.

AEK
AEK
SuperUser
SuperUser
November 25, 2025

Indeed in case there is NAT device in front of your FGT then you will see the public IP of that NAT device.

AEK
ElwinBERRAR
Explorer III
November 28, 2025

If you’re seeing a 10.x source on FAC Cloud, it means there’s an intermediate NAT device rewriting the source before it reaches the internet. FAC Cloud will always display the final source IP it receives.

https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/188051/source-nat
https://pingmynetwork.com/network/ccna-200-301/why-nat-was-created