We are planning to utilize a RADIUS server for LDAP and OTP authentication. Our objective is to send the Username, Password, and OTP in a single request. To achieve this, we need to create a Custom Vendor-Specific Attribute (VSA) in the FortiGate firewall. This will enable us to include the OTP along with the Username and Password for authentication purposes. Could you please provide the detailed procedure for creating a Custom VSA in the FortiGate firewall?
Solved! Go to Solution.
Hi @robinh007 ,
I am unfamiliar with Radius and have never heard of including a Username, Password, and OTP in one Radius request.
Here is the article about Fortinet's RADIUS Dictionary and VSAs (latest):
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi @robinh007 ,
I am unfamiliar with Radius and have never heard of including a Username, Password, and OTP in one Radius request.
Here is the article about Fortinet's RADIUS Dictionary and VSAs (latest):
I think it depends on the authentication protocol (PAP, CHAP, MSCHAP2 & EAP). Some support challenge response, some support concatenated password-OTP and some may support both.
We have defined the protocol as PAP in our radius server.
PAP is insecure but it supports password-token concatenation.
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.