Hi,
I would like to ask if it's possible to return the Administrator username as a radius attribute from FAC to FMG, I know that I can return the access profile, but I would like to also return the wildcard user to use on FMG.
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello, Would you mind elaborating a bit more on what exactly you're trying to accomplish? What do you need the username for and how are you planning on using it? Is there any scripting involved? Regards
Hi, let's imagine ... Network diagram:
- Admin person [Alice] --> FMG -> client side {RADIUS} server side -> FAC
FMG:
- uses wilcard admin config, pointing to user group on FMG
- that user group points to RADIUS server config on FMG
- that RADIUS server config on FMG points to FAC as actual AAA RADIUS server
And so as FMG is the RADIUS client, then it sends out Access-Request to FAC.
And as you would see in packet capture there is "User-Name" AVP, filled by FMG with login name used by actual administrator [Alice] who tried to login to FMG.
As the FMG uses Wildcard type of admin to point out to FAC (through designated user group), then it is most probably not sending that wildcard profile name (never seen that to be sent in the past, but haven't tested FMG in about past year).
Therefore FAC knows nothing about used wildcard profile, and the only known thing is the true login name used in logon attempt and sent as User-Name.
I'm not sure why would you need to know wildcard profile name (if I got you correctly).
Maybe to filter RADIUS Service / Policies based on received "RADIUS attribute criteria".
In that case have a look into packet capture. Not sure for FMG but FGT does send Connection-Info from which you can determine if the logon is made to admin GUI, or SSL VPN, or IPSec VPN, or it's CLI/GUI logon test ...
There will be no wildcard profile name as we do not have that in our dictionary.
However to distinguish between admins there might be access profile usefull, or RADIUS group match set as well.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1665 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.