Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ismailurek2
New Contributor III

FortiAuthenticator Usage Profile Not running

Hello, 

 

I want to limit the VPN connection of local or imported ldap user as data and time using usage profile on FortiAuthenticator. I am listening on 1646 radius acconting. 1646 port is open on FortiGate and FortiAuthenticator. When the user exceeds the specified limit, no warning and interruption is observed. Can anyone realize this application or have any suggestions? By the way, when the user connects, I cannot see any session in Monitor > Radius Session field.

 

I have followed all the warnings in this document:

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Usage-Profiles-not-enforced-for-R...

 




3 REPLIES 3
ebilcari
Staff
Staff

Firstly you can run a packet capture in FAC to verify that indeed the Accounting messages are reaching FAC. Later you can check from the debugs, https://fac/debug/ [Accounting Monitor] logs to get a better overview on what is happening.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ismailurek2
New Contributor III

Hi @ebilcari ,

When I look at the accounting monitor, I get an invalid error in this way. I do not have information about which field to apply the secret I set for accounting on the FortiGate side on the FortiAuthenticator side.

 

image.png

ebilcari

The secret for accounting messages should be the same as the one used for authentication, remember to also enable this toggle:

shared-acc.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors