This article describes how to create a user-based VPN policy with RADIUS without usergroup authentication on FortiGate. It offers detailed, step-by-step guidance on configuring a user object with RADIUS authentication and applying it to a firewall policy.
FortiGate.
To configure a user-based VPN policy with RADIUS authentication on FortiGate, follow these instructions:
After configuring the user-based VPN policy, test the connection to ensure it is working as expected.
Note: Make sure that in IPsec VPN phase1 configuration, the xauth user group is set 'inherit from policy' in the GUI, or 'set xauthtype auto' in the CLI.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.