Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dukath
New Contributor

SSL VPN - Combining LDAP and Radius authentication

Hey,

 

I am currently investigating a migration to MFA for the SSL VPN. Currently LDAP authentication is used and for MFA we have set up a radius server that provides MFA (microsoft authenticator). On its own the MFA works perfectly on a test system. Since we cannot migrate all users to MFA simultaneously, the idea is to slowly move end users from ldap to radius auth but i have not been able to get this to work.

 

If i add Radius to the SSL groups, a user logging in will get the MFA request but gets logged in before he can even accept or deny. I suspect this is due to the fact that fortigate queries all auth servers and takes the first result. Since ldap does not need to wait for the MFA comfirmation, this is always going to be first.

 

If i remove the end user from the VPN group in AD, then authentication fails before he gets the chance to accept or deny the MFA request. Again I suspect this is due to the fact that LDAP answers first. Authentication to LDAP succeeds, but the list of AD groups does not contain the one requested for VPN and thus authorization fails.

 

Is there any way to force fortigate to try radius first and if it fails then fallback to LDAP, or to wait for Radius even though LDAP auth succeeds but does not have the required groups?

 

If not, any suggestions on how to slowly migrate end users to MFA?

 

Thanks

3 REPLIES 3
guillaume66
New Contributor

Hello dukath Did get an answer on your question ? Looking to do something similar Thnks
boneyard

i have tested with something similar and i dont believe what you want is possible within normal configuration. it does indeed fall through and try the next.

 

you might try with different realms and request people to try another realm when they are moved.

 

https://docs.fortinet.com...72/ssl-vpn-multi-realm

Yurisk

As you already noticed, there is no way to prefer Radius/LDAP in the same remote users group. IF I were to do this I'd try to separate users by groups/protocols and then used the Top-Down rule matching logic - higher VPN SSL rules would use groups with Radius authentication, lower security rules would use LDAP-based user groups. Fortigate starts from the top and checks every VPN SSL rule to find matching remote group/authentication server, so it would 1st try to match groups/users on Radius server, and if not found then would try LDAP servers.

 

Unrelated - mixing authentication servers in the same rule may/will cause troubles, for back up purposes there is a command under authentication server config to specify secondary server/additional IP in case the main one fails.

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Labels
Top Kudoed Authors