Skip to main content
Steve_A
New Member
July 19, 2021
Question

SSL VPN - RADIUS AUTH with LDAP USER GROUPS

  • July 19, 2021
  • 2 replies
  • 4325 views

Hello Guys,

 

I am a bit stuck on something I want to achieve, but not sure how to complete the required.

Please see the below low down:-

Successfully create a RADIUS and LDAP Server, with a successful query.

I have created two SSL VPN Portals

[ul]
  • Split Tunnel
  • Full Tunnel[/ul]

    From each of the portals I want the following to happen:-

    [ul]
  • Both Portals will use RADIUS Auth (this is key)
  • Split Tunnel Portal would use RADIUS AUTH[ul]
  • LDAP QUERY would look into AD and a users group Split_Tunnel would infact get Split Tunnel[/ul]
  • Full Tunnel Portal would use RADIUS AUTH[ul]
  • LDAP Query would look into AD and a user group Full_tunnel would route all traffic down the tunnel[/ul][/ul]

    Is it possible, for a RADIUS Auth user, to get the relevant SSL VPN Portal config, based on their LDAP query?

     

    I have achieved the above previously with Juniper/Pulse, but this is my first time trying with the Fortigate. Running latest version 7.0.1 (as 7.0 broken LDAP queries from the GUI and I was getting ldap-3) :) 

     

    Any help much appreciated!

    • 2 replies

      yigiton
      New Member
      January 15, 2022

      Hi

       

      You radius server check LDAP for authentication and return relevant group information. 

       

       

      Debbie_FTNT
      Staff & Editor
      Staff & Editor
      January 17, 2022

      Hey Steve,
      FortiGate would NOT perform an LDAP query after RADIUS auth.
      It would allow getting group information from the RADIUS reply itself and matching local user groups on FortiGate based on the RADIUS attributes. The SSLVPN portal (and split-tunneling) would be selected based on group information in the RADIUS reply.
      You might want to check this:
      https://community.fortinet.com/t5/FortiGate/Technical-Tip-A-quick-guide-to-FortiGate-SSL-VPN-authentication/ta-p/202041
      https://community.fortinet.com/t5/FortiGate/Technical-Tip-Authentication-Remote-server-group-match-of-user/ta-p/190905
      essentially:
      - ensure your RADIUS server response includes the Fortinet-Group-Name attribute
      -> depending on the RADIUS server, you can ensure that it includes the Fortinet-Group-Name based on LDAP group lookup (something roughly like this can be done on FortiAuthenticator, for example)
      - match into groups on FortiGate based on this attribute
      - match SSLVPN portal based on the group
      Fortinet RADIUS dictionary:
      https://community.fortinet.com/t5/FortiDDoS/Technical-Tip-Fortinet-RADIUS-attribute/ta-p/194896
      I hope that helps :)

      Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!