Skip to main content
WANAccounts
New Member
September 23, 2024
Question

TACACS+ Not Reading User Group for Remote Users

  • September 23, 2024
  • 1 reply
  • 844 views

Hi there,

I am currently using FortiAuthenticator as the TACACS+ sever for our enviornment. All of my admin users are imported via LDAP.

When I assign a TACACS Profile directly to the user, the user is able to successfully authenticate to devices. 
If I remove the TACACS profile and assign the TACACS profile to a User Group that contains the User, the TACACS debug logs shows successful Authentication, but Authorization fails because TACACS reports that the user is not in a group which has a TACACS profile.

If I do the same thing with a Local Group that contains Local Users, the inheritance of TACACS Profile works just fine.

Has anyone else experienced this issue?

FAC version = v6.4.7, build1054 (GA)

1 reply

jhussain_FTNT
Staff
Staff
September 25, 2024

Hi,

 

Please check the configuration as per the document below and let us know the status.

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-FortiAuthenticator-as-TACACS-server-for-FortiGate/ta-p/275156

 

Regards

Jamal Hussain

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!