Created on
09-21-2023
08:51 AM
Edited on
09-22-2023
01:16 AM
By
Jean-Philippe_P
Description |
This article describes how to configure FortiAuthenticator as a TACACS+ server for FortiGate user authorization. FortiAuthenticator can perform central authentication as TACACS+ Server and Authorize the admin profile used on FortiGates. |
Scope |
Specific users on FortiAuthenticator should be able to authenticate and access the FortiGate with the appropriate admin profile. |
Solution |
Generic TACACS+ configuration information can be found for both Fortigate and FortiAuthenticator products in the Fortinet Document Library.
For Example: FortiGate:
FortiAuthenticator:
The below link details the required Fortigate configuration: Remote administrators with TACACS VSA attributes
Configuring FortiAuthenticator Authorization: The below is an Authorization Service that when configured can be allowed in an Authorization Rule and will return the appropriate Vendor-Specific Attributes (VSAs) to the FortiGate during authentication/authorization.
Go to Authentication -> TACACS+ Service -> Authorization, Select Services from the top right menu.
Note: If the 'set vdom-override' option has been set to 'enable' under the admin user configuration on the FortiGate, then the VDOM VSA can also be configured on the FortiAuthenticator if required (example below):
Go to Authentication -> TACACS+ Service >- Authorization, and select Rules (default) from the top right menu. |