Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zolemfo1
New Contributor

802.1x RADIUS token to bind user firewall policys

Hello. In my lab environment I am trying to setup 802.1x with dynamic vlan assignment which I have successfully configured. However I would like to build out on this even more and try to make fw policys based on the user, so is it possible to use the same "token" that I use to authenticate the user with 802.1x to create firewall policys with this instead of prompting the user to authenticate again to recieve their firewall policys? Any suggestions? Is it even possible?

10.0.0.0.1 192.168.1.254
2 REPLIES 2
ebilcari
Staff
Staff

This can be achieved by configuring RSSO, Configuring RADIUS SSO authentication.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
AEK
SuperUser
SuperUser

Hello

As far as I know, FGT can't know the user from RADIUS request/response. However, in case you don't already have NAC or ZTNA solutions (that can help with group tags), then you may achieve what you are looking for with RSSO, since FGT can read RADIUS accounting messages.

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/85730/radius-single-sign-on-rsso-agent

Hope it helps.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors