Created on 07-05-2022 11:14 AM Edited on 07-31-2024 08:28 AM By Stephen_G
Description
This article explains why FortiAuthenticator is not sending the 'Fortinet-Group-Name' AVP in the Radius Access-Accept message.
Scope
FortiAuthenticator v6.6.1.
Solution
When capturing the Radius traffic between FortiAuthenticator and FortiGate, shown in the screenshot, FortiAuthenticator does not send 'Fortinet-Group-Name' AVP.
Radius attributes and user group settings are configured further on the FortiAuthenticator:
FortiGate as a Radius client is configured. In the Radius policy, the 'Identity source' LDAP server is defined. Additionally, enable 'Filter' and select a user group that was configured. For example: sslweb.
Now, in packet capture, 'Fortinet-Group-Name' AVP can be seen.
Related article:
Technical Tip: Radius authentication with FortiAuthenticator
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.