FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
ramosd
Staff
Staff
Article Id 373927
Description This article describes how to debug the RADIUS service on FortiAuthenticator for troubleshooting purposes.
Scope FortiAuthenticator.
Solution

To access FortiAuthenticator debug logs access: 'https://x.x.x.x/debug/radius/ (Replace x.x.x.x with the FortiAuthenticator GUI IP):

 

FAC RADIUS DEBUG.PNG

 

  • Set Max. log files size to 500 MB.
  • Enter debug mode before sending the authentication request.

 

Lines500.PNG

 

  • Set to 500 lines the number of lines to see more information per page.
  • Send the authentication request, refresh the page, and verify the debug logs.
  • Use ctrl + F to find the username or use the search bar:

 

Searchbar.PNG

 

Sometimes it is necessary to have more information on Radius debug logs by entering in 'Detail Debug Mode' and selecting twice 'Enter in debug mode' from https://<fac-ip>/debug/radius.

 

Radiusdebug.png

 

This can be done as well from the CLI of FortiAuthenticator.

 

debug radius 2

 

radius debug1.png

 

Download the debug log file and share it with the FortiAuthenticator support team for deep troubleshooting.

Related articles:
Troubleshooting Tip: How to work with FortiAuthenticator Technical Support. 

Troubleshooting Tip: How to debug FortiAuthenticator Services.