FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
RobBlenk
Staff
Staff
Article Id 254893
Description

This article shows a possible cause of failed authentication to a TACACS+ server when the connection to the server is up and user credentials are good.

Scope FortiGate v6.x.x and v7.x.x.
Solution

Connect to the TACACS+ server in the GUI shows 'Connected'.

 

diagnose test authserver tacacs+ <servername> <username> <password>  <----- Connection test succeeds.

 

However, a packet capture will show failed connections.

 

Picture1.png

 

In this case, uncheck 'Include in every user group' in the RADIUS config.

 

include.png

Contributors