FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pmeet
Staff
Staff
Article Id 239431

Description

While using RADIUS in addition to another auth server for authentication, FortiGate sometimes uses the wrong policy. The RADIUS server is not mentioned in the group but authentication still occurs through the RADIUS server.

Scope

FortiGate.

Solution 

See documentation for more information on RADIUS server authentication:

https://docs.fortinet.com/document/fortigate/6.0.0/handbook/634373/authentication-servers#RADIUS_ser... 

 

To fix this issue, follow the steps below:

 

1) Under User and authentication -> Radius Servers, choose the intended RADIUS server.

2) Under the configuration, look for the Include in every user group' option.

 

If the option is enabled, disable it as it will include the RADIUS server in all groups of the firewall.

 

pmeet_0-1670874619242.png

  

pmeet_1-1670874619244.png

 

Contributors