I have a, maybe silly question but maybe someone can answer me..
We have FAC setup with RADIUS clients in a 10.10.0.0/16 subnet, mainly used towards switches for MAB.
The thing is we want to configure VPN for a firewall with an IP in the same subnet. Is it possible to configure this as a /32 without it being affected in the /16 subnet policy?
Solved! Go to Solution.
I solved this by alternating shared secrets.
But I did not get an answer on my question regarding matched Radius attribute. Is it a limitation to match on exact string/integer or is it possible to use regexp (or similiar)?
You can only match to a substring with the given option if present ("Allow substring match").
Regex or wildcards are not possible.
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi again,
I maybe found something:
To handle duplicate entries for a RADIUS client in FortiAuthenticator, you can differentiate between policies using specific RADIUS attribute criteria.
Sounds like you are on to something, thanks for your reply.
In the Attribute Criteria, I need to find something synonymous for the RADIUS- clients. I wanted to test with nas-identifier. Seems the string needs to match exactly, I could not find begins-with/ends-with or contains. Is this a limitation or could I use for example regular expressions?
I would suggest to follow the long path to avoid any faults, try to divide the super subnet /16 to smaller ones and leave the FGT subnet out of it. The shared secret matching for all the devices may also be an issue.
If that is not doable, you can specify a different IP from the FGT to source its RADIUS requests. If all of the existing IPs of the FGT still fall under the subnet 10.10.0.0/16 you can also create a loopback as long as it's routed to FAC, more details can be found on this section of the guide.
Thanks for your response. I will look into how much work it will cause since it's in aew production environment.
As for my above question regarding matched Radius attributes, is it a limitation to match on exact string/integer or is it possible to use regexp (or similiar)?
Created on 03-17-2025 05:21 AM Edited on 03-17-2025 05:21 AM
Anyone?
I solved this by alternating shared secrets.
But I did not get an answer on my question regarding matched Radius attribute. Is it a limitation to match on exact string/integer or is it possible to use regexp (or similiar)?
You can only match to a substring with the given option if present ("Allow substring match").
Regex or wildcards are not possible.
User | Count |
---|---|
2571 | |
1365 | |
796 | |
652 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.