Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
robinh007
New Contributor

Creation of Custom VSA

We are planning to utilize a RADIUS server for LDAP and OTP authentication. Our objective is to send the Username, Password, and OTP in a single request. To achieve this, we need to create a Custom Vendor-Specific Attribute (VSA) in the FortiGate firewall. This will enable us to include the OTP along with the Username and Password for authentication purposes. Could you please provide the detailed procedure for creating a Custom VSA in the FortiGate firewall?

 

FortiGate  

h007robin
h007robin
3 REPLIES 3
Stephen_G
Moderator
Moderator

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen - Fortinet Community Team
dingjerry_FTNT

Hi @robinh007 ,

 

I am unfamiliar with Radius and have never heard of including a Username, Password, and OTP in one Radius request.

 

Here is the article about Fortinet's RADIUS Dictionary and VSAs (latest):

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Fortinet-s-RADIUS-Dictionary-and-VSAs-late...

 

 

Regards,

Jerry
AEK
SuperUser
SuperUser

I think it depends on the authentication protocol (PAP, CHAP, MSCHAP2 & EAP). Some support challenge response, some support concatenated password-OTP and some may support both.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors