FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
ychia
Staff
Staff
Article Id 357341

 

Description

This article describes the issue when connecting to Radware integrating with FortiAuthenticator TACACS+ service:

 

FAC-TACACS+.JPG

 

Screenshot from FortiAuthenticator GUI under Authentication -> TACACS+ Service -> Authorization -> Services.

 

Below are the TACACS+ debug logs from FortiAuthenticator:


2024-11-09T13:47:05.222819+08:00 FortiAuthenticator tac_plus[22046]: bind to [::]:49 succeeded
2024-11-09T13:47:05.222895+08:00 FortiAuthenticator tac_plus[22046]: bind to [::]:4949 succeeded
2024-11-09T13:47:05.232407+08:00 FortiAuthenticator tac_plus[22053]: Error /usr/etc/tacdb/tac_plus.cfg:229: Expected 'acl', 'default', 'double-quote-values', 'message', 'optional', 'protocol', 'return', 'script' or 'set', but got '['
2024-11-09T13:47:05.236298+08:00 FortiAuthenticator tac_plus[22052]: Error /usr/etc/tacdb/tac_plus.cfg:229: Expected 'acl', 'default', 'double-quote-values', 'message', 'optional', 'protocol', 'return', 'script' or 'set', but got '['
2024-11-09T13:47:05.240141+08:00 FortiAuthenticator tac_plus[22054]: Error /usr/etc/tacdb/tac_plus.cfg:229: Expected 'acl', 'default', 'double-quote-values', 'message', 'optional', 'protocol', 'return', 'script' or 'set', but got '['
2024-11-09T13:47:05.244086+08:00 FortiAuthenticator tac_plus[22055]: Error /usr/etc/tacdb/tac_plus.cfg:229: Expected 'acl', 'default', 'double-quote-values', 'message', 'optional', 'protocol', 'return', 'script' or 'set', but got '['
<More...>
2024-11-09T13:47:05.272635+08:00 FortiAuthenticator tac_plus[22046]: Child reported fatal configuration problem. Exiting.
2024-11-09T13:47:05.273952+08:00 FortiAuthenticator tac_plus[22052]: Error Detected fatal configuration error. Exiting.
2024-11-09T13:47:05.274781+08:00 FortiAuthenticator tac_plus[22054]: scm_send_msg: sendmsg: Connection refused

Scope FortiAuthenticator.
Solution

Add double quote for radware-role and radware-policy:

  • "SYS+ADMIN:[ALL]"
  • "[ALL]:[ALL]"

 

FAC-TACACS+withQuote.JPG

 

Contributors