FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
hvardhang
Staff
Staff
Description

This article describes the scenario when a FortiAuthenticator is acting as Radius server.

Whenever, there is the Access Request the Fortiauthenticator by default checks in Remote/Local users.

Scope

In a wide scenario, it would be difficult to add the Radius Vendor Specific Attributes for each individual user.

The option available would be Group based search and match the attributes configured in user groups.

Solution

Note.

If there are users and user groups, by default Fortiauthenticator matches the user and send the information to Radius client.

 

To match the User groups and send the Vendor Specific attribute information to Radius client, it is necessary to add the Filter.

 

Navigate to Radius Service -> Policies -> Identity Source -> Filter under groups and add the required groups.

 

This will take preference search first for Groups rather than users.

 

hvardhang_0-1640326911686.png
Contributors