FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
ssriswadpong
Staff & Editor
Staff & Editor
Article Id 324696
Description This article describes how to create a remote wildcard domain admin for FortiMail with FortiAuthenticator as a Radius server.
Scope FortiAuthenticator, FortiMail.
Solution

In this example, there are 2 domains in FortiMail.

  • domain1.test.
  • domain2.test.
 

The objective is to create a remote wildcard admin for a specific domain.

 

Screenshot 2024-07-08 153338.png

 

To configure:

  1. FortiMail WebGUI (Advanced View)-> Profile -> Authentication -> Radius -> New.

Create a new Radius profile and enable 'Enable remote domain override'.

 

Screenshot 2024-07-08 153743.png

 

  1. FortiMail WebGUI (Advanced View)-> System -> Administrator -> Edit the existing profile 'remote_wildcard'.

  • Enable this profile.
  • Select Authentication type: RADIUS.
  • Select RADIUS profile: the newly created profile from 1.

 

Screenshot 2024-07-08 154052.png

 

  1. On FortiAuthenticator, create 2 domain users. In this example, local user 'domain1admin' is an administrator of domain1.test, and 'domain2admin' is an administrator of domain2.test. These domain admins will not be able to access the other domain.

    FortiAuthenticator WebGUI -> Authentication -> User Management -> Local Users.


Screenshot 2024-07-08 154656.png

 

After creating the admin account, editing the account, configure the RADIUS Attributes:

  • Vendor: Fortinet.
  • Attribute ID: Fortinet-Vdom-Name.
  • Value: <enter the domain name> (In this example, domain1.test for domain1admin and domain2.test for domain2admin).

 

Screenshot 2024-07-08 154922.png

 

Screenshot 2024-07-08 155302.png

 

  1. On FortiAuthenticator, create Radius client and Radius policy.

  • FortiAuthenticator WebGUI -> Radius Service -> Clients -> Create New for FortiMail.


Screenshot 2024-07-08 155741.png

 

  • FortiAuthenticator WebGUI -> Radius Service -> Policies -> Create New for FortiMail.


Screenshot 2024-07-08 155728.png

 

To verify:

Login FortiMail with domain1admin and check the domain on FortiMail. The account 'domain1admin' have access to only domain1.test and the account 'domain2admin' have access to only domain2.test.

 

Screenshot 2024-07-08 160137.png

 

 Screenshot 2024-07-08 160111.png