FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
matanaskovic
Staff
Staff
Article Id 216821

Description

 

This article explains why FortiAuthenticator is not sending the 'Fortinet-Group-Name' AVP in the Radius Access-Accept message.

 

Scope

 

FortiAuthenticator v6.6.1.

 

Solution

 AVP.nullAVP.null

 

When capturing the Radius traffic between FortiAuthenticator and FortiGate, shown in the screenshot, FortiAuthenticator does not send 'Fortinet-Group-Name' AVP.

 

Radius attributes and user group settings are configured further on the FortiAuthenticator:

 

AVP.testAVP.test

 

FortiGate as a Radius client is configured. In the Radius policy, the 'Identity source' LDAP server is defined. Additionally, enable 'Filter' and select a user group that was configured. For example: sslweb.

 

radius.policy.JPG

 

Now, in packet capture, 'Fortinet-Group-Name' AVP can be seen.

 

AVP.test1.png

 

Related article:

Technical Tip: Radius authentication with FortiAuthenticator