Skip to main content
suthomas1
New Member
January 21, 2019
Solved

remote access

  • January 21, 2019
  • 17 replies
  • 29025 views

All,

In setting up a fortigate unit for remote users to access local lan of our enterprise, 3 vdom has been used with vdoms serving 3 causes - vpn termination, secure vdom & root. vpn vdom has virtual links created to vpn vdom & secure vdom. Question is:-

1) for users authentication with radius, will it be using vpn vdom or root vdom? 2) If vpn vdom , how will the routes be towards the inside to reach authentication server?

please help. thank you.

    Best answer by Toshi_Esumi

    Supposed to be the admin user name and password you want to authenticate with. However, GUI version of "test connectivity" doesn't actually show pass or fail of the user name/pass. If something comes back from RADIUS it would show "success" so not much better than just pinging the server from the outgoing interface. In other words, you can put a bogus username/password.

    If you really want to "test RADIUS", you have to use a CLI:

    # diag test authserver radius <server_name> pap "<user_name>" "<password>"

     

    17 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    January 21, 2019

    RADIUS server is configured at each vdom. The other vdoms don't know or don't care what is the RAIUS IP another vdom has. The vpn vdom needs to have a route to get to the RADIUS server you configured regardless if it's over the internet or internal interface. If the internal interface is not attached to the vdom but attached to another vdom, you need to have a vdom-link then a route toward the vdom that has the internal interface.

    suthomas1
    suthomas1Author
    New Member
    January 22, 2019

    thanks for the response. if the route needs to be via management interface , does it matter if the management interface resides in root and not on the actual remote access termination vdom?

     

    Toshi_Esumi
    SuperUser
    SuperUser
    January 22, 2019

    Do you mean "management interface" as an interface you use for management access, like https and ssh? If so, management access can be any interface at any vdom. As long as your admin privilege is "suer_admin"  you can hop around vdoms as well as global.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!