FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
guptas
Staff
Staff
Article Id 258735
Description This article describes how to configure TACACS+ login for a user of an AAA server.
Scope FortiWeb and an AAA server.
Solution

In the FortiWeb configuration for an AAA server, navigate to User -> Remote Server -> TACACS+ Server -> Create New.

 

TACACS server config in FWEB1.jpg

 

Create an Admin Group and add the TACACS+ User entry in the above step under User -> User Group -> Admin Group.

 

Admin group to add tacacs+1.jpg

 

Admin group to add tacacs+3.jpg

 

Create an Administrator account and select the above entry created before under System -> Admin -> Administrators -> Create New -> Administrator.

 

Fortiweb-Admin.jpg

 

Note: The username configured in the Active Directory/AAA server should match exactly with the username in the FortiWeb configuration under Admin.

If the intention is for the AAA server to send an access profile to FortiWeb, configure Authorization in the AAA server with the following settings:

 

authorization-service.jpg

 

authorization-service1.jpg

 

Note: If the AAA server is not configured to send authorization from an AAA server, FortiWeb will assign access profiles configured with users.

 

To configure FortiAuthenticator, see the following documentation:

https://docs.fortinet.com/document/fortiauthenticator/6.5.2/administration-guide/791531/tacacs-servi...

Contributors