Description |
This article describes how to enable password renewal for SSL VPN RADIUS users.FortiGate can process the renewal of expired passwords for Radius users during the user's login. In this example, the RADIUS server is a Windows NPS Server. A user radiususer is configured on the Windows NPS server with force password change on the next logon. |
Scope |
FortiGate. |
Solution |
Password renewal will only work with radius using the MS-CHAP-v2 authentication method.
To enable password renewal in FortiGate:
config user radius edit "Radius" set server "10.230.0.2" set secret <passwd> set auth-type ms_chap_v2 set password-renewal enable next end
On the Windows NPS Radius server, see the below screenshots for reference of configuration:
Connection Request Policies: Enable 'MS-CHAP-v2' and 'User can change the password after it has expired'.
Network Policies: Enable 'MS-CHAP-v2' and 'User can change the password after it has expired'.
To change the expired password, log in to the VPN using the existing password. Upon login, the message 'Your password expired. Please provide a new one.’ this should prompt. Enter the new password.
Note: It is not possible to use the previously used passwords on the renewal. A new password should meet the complexity requirements of the organization.
If the new password does not meet the requirements, the error ‘New password maybe not meet the policy’ will prompt.
If the password change is successful, it will allow connecting to the VPN after the password change.
The same process will go if using SSL VPN web mode. Upon login, the message ‘Your password expired. Please provide a new one.’ This should prompt.
If the password change is successful, it will allow the user to connect to VPN.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.