Hello. In my lab environment I am trying to setup 802.1x with dynamic vlan assignment which I have successfully configured. However I would like to build out on this even more and try to make fw policys based on the user, so is it possible to use the same "token" that I use to authenticate the user with 802.1x to create firewall policys with this instead of prompting the user to authenticate again to recieve their firewall policys? Any suggestions? Is it even possible?
This can be achieved by configuring RSSO, Configuring RADIUS SSO authentication.
Hello
As far as I know, FGT can't know the user from RADIUS request/response. However, in case you don't already have NAC or ZTNA solutions (that can help with group tags), then you may achieve what you are looking for with RSSO, since FGT can read RADIUS accounting messages.
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/85730/radius-single-sign-on-rsso-agent
Hope it helps.
User | Count |
---|---|
2559 | |
1356 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.