Hello
When configuring FortiManager with Cisco ISE RADIUS Server, FMG don't attribute the good profile to the user as asked by ISE.
You find below my configuration:
On ISE side:
[ol]on FMG side:
[ol]The problem is when I connect on the FMG with a user member of GROUP-RO, ISE send the necessary attributed of the Access Profile with PROFILE_RO, but the FMG consider the user as member of another profile as described below.
# diagnose system admin-session list
*** entry 7 *** session_id: 12427 (seq: 0) username: user_ro admin template: GROUP-RW from: GUI(1.1.1.1) (type 1) profile: SUPERUSER (type 1) adom: root session length: 559 (seconds)
idle: 301 (seconds)
Anyone has any idea how to resolve this issue?
Thank you for your help!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.