Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

FWB HTTP authentication via RADIUS with FAC

Hello

FortiWeb 6.3.9 and FortiAuthenticator 6.4.9.

My FWB is configured to authenticate admins (for admin access) via RADIUS authentication with FAC and it works just fine.

This issue comes when I want to use HTTP authentication, for users when they want to access some protected Web servers.

I configured like explained here:

https://docs.fortinet.com/index.php/document/fortiweb/6.3.9/administration-guide/467409

Now when a user tries to access a protected server, it shows HTTP authentication window, but when user enters correct username and password, FWB still returns error 401 (unauthorized), even if my FAC logs show the related authentication was successful.

For info on FWB's RADIUS config, when I test the authentication with the same credentials it works fine.

AEK
AEK
6 REPLIES 6
holinbo1
New Contributor

RADIUS is still the method to connect authentication of networking devices to your domain. Move to WPA2-enterprise and have users login with domain creds. They instantly lose connectivity if their credentials are disabled / locked https://mobdro.bio/ .

AEK

This response is off topic.

AEK
AEK
kwcheng__FTNT

When FortiWeb repeats HTTP 401, it simply means the authentication failed. Since you had confirmed that the authentication passed in the Fortiauthenticator, perhaps it is caused by timeout setting if it took more than 2 seconds for the FAC to response back.

 

You can check the explanations here:

a) Error 401:

https://help.fortinet.com/fweb/583/Content/FortiWeb/fortiweb-admin/offloading_http.htm

b) timeout issue:

https://docs.fortinet.com/index.php/document/fortiweb/6.3.9/administration-guide/467409

 

Regards

Patrick

Do you need to configure a static route when passing an apple from left hand to right hand?
AEK

Thanks for your response, Patrick.

Yes I confirm the authentication is successful. I also confirm there is no timeout because I enabled debug logs on FWB and the event logs show that the authentication is reported successful on FWB as well.

Any other idea?

AEK
AEK
kwcheng__FTNT

As said, receiving 401 errors simply indicating the FWB still unable to authenticate the users successfully. Whether the FWB is waiting for a specific response from FAC or the received packet is not identifiable, you might want to initiate a TAC ticket to verify.

 

Regards

Patrick

Do you need to configure a static route when passing an apple from left hand to right hand?
AEK

Thanks Patrick

I'll follow your recommendation and initiate a ticket.

Meanwhile any other idea is welcome.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors