Skip to main content
fvelazquez
New Member
October 6, 2016
Question

Source-IP command under "config user tacacs" not working,

  • October 6, 2016
  • 3 replies
  • 5716 views

Hello, currently I just did a setup of tacacs+ on FortiGate 100D v5,2,5 build 701. After all this config, I put the command "source-ip" because I wanted to use an internal address to make request for tacacs. But after doing a test under the GUI for connectivity, I realized that my "set source-ip" command is not considered, because the petitions for tacacs go from the egress interface as if the "source-ip" command is not take into consideration, and it fails. What is wrong with the config? Did I miss something? Actually when I run the command "get system source-ip status" it states that tacacs is using 192.168.145.1 as I configured, but in the sniffer capture it shows the egress interface making the requests, which is not correct. Any ideas? please.

 

 

Regards,

 

 

 

 

3 replies

fvelazquez
New Member
October 10, 2016

Any ideas please?

 

Regards,

toy4two
New Member
June 30, 2017

I've learned there is a bug if you try to source from a Loopback address, same behavior, is that what you are doing?  If so try a Physical interface (not sure I can even use a VLAN interface!)

emnoc
New Member
July 2, 2017

This is not a bug, this is a limitation in the test command that you can't "set the source ip". if you run the diag test command from  the cli you have the exact same problem btw.

 

 

Kem

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!