Skip to main content
DaveCSuite
New Member
October 5, 2021
Question

Trying to connect Fortigate to Radius Server (FortiAuth) over IPSec

  • October 5, 2021
  • 6 replies
  • 8661 views

I have an established IPSec tunnel with 1 host on each side. Windows AD is local (192.168.11.254) and FortiAuth is remote (1.0.0.231). I have good traffic and the Auth is able to import LDAP users and shows a valid connection.

 

I am trying to add the Forti 80CM as a Radius client and the test fails.  I ran ping and traceroute from the CLI on the firewall with no success. I ran sniffer and see there is nothing with the firewall IP in the output. 

 

Policy is wide open, source and destination are "all" and service is "all". No NAT, no security policies.

 

 Do I need to add the firewall to the VPN policy?

I have a feeling I'm missing something easy.

 

diagnose sniffer packet 'VPN AEWS Static' none 4 interfaces=[VPN AWS Static] filters=[none] 4.255542 VPN AWS Static -- 10.0.0.231.54034 -> 192.168.11.254.445: psh 3524084358 ack 1433518151 4.256254 VPN AWS Static -- 192.168.11.254.445 -> 10.0.0.231.54034: psh 1433518151 ack 3524084566 4.289899 VPN AWS Static -- 10.0.0.231.54034 -> 192.168.11.254.445: ack 1433518315 4.290021 VPN AWS Static -- 10.0.0.231.54034 -> 192.168.11.254.445: psh 3524084566 ack 1433518315

    6 replies

    supportombm
    New Member
    October 5, 2021

    Hi,

    i think the problem is whenever you configure something from GUI it always use the internal interfaces (such as lan and wan).

    i had that problem with a remote LDAP server.

    If you edit that Radius in the cli you should be able to se a source-ip

       set source-ip {string}   Source IP address for communications to the RADIUS server. size[63]

    https://docs.fortinet.com/document/fortigate/6.0.0/cli-reference/918082/user-radius

     

    let me know

    DaveCSuite
    New Member
    October 5, 2021

    Thanks, I'm not sure what IP to use as the source since I need it to go over the tunnel. I tried the WAN ip the tunnel is bound to without success. I wonder if I can use the name of the tunnel as a source? I'll give that a shot and reply.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!