FortiAuthenticator
FortiAuthenticator provides access management and single sign on.
rbraha
Staff
Staff
Article Id 221250

Description

 

This article describe how to can login in FortiAuthenticator as an administrator from an external radius server.

 

Scope

 

FortiAuthenticator

 

Solution

 

In this article two FortiAuthenticator are used, one is Radius client and the second is a Radius server.

 

On the second FortiAuthenticator configured as Radius server, the first FortiAuthenticator is added as Radius client and also added in the radius policy.

 

    client rad,server.png

 

rad policy 1.png

 

Other tabs on the radius policy remains the same, only in identity source one can specify realm and user group that has been created before for users imported from AD side.

 

identity source.png

 

To import LDAP user from AD and creating realm on FortiAuthenticator, follow this below KB articles . The remote users can have token for 2FA authentication .

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-import-remote-LDAP-user-in...

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-FortiAuthenticator-realm-based-au...

 

users.png

 

On the first FortiAuthenticator , create new radius under Authentication - > Remote Auth. Servers - > Radius - >Create 

 

client1.png

 

Under User Management - > Remote Users select Radius - > Create New 

 

Create the new user as administrator and give full access permissions  with the same username as the user imported from the second FortiAuthenticator as Radius server .

 

user1.png

 

Create an user group and add this user in this group 

 

user 2.png

 

Create realm here, with same name as domain and as user source select Radius server.

 

realm2.png

 

Go to System Access - > Administration  and the section Realm, select the realm and the group that was created before.

 

system access png.png

 

Test by logging in using the username: gatuzo and the login was successful.

 

user loginpng.png

 

From the second FortiAuthenticator as radius server check the radius debug logs.

 

debug logspng.png

Contributors