Hello,
I am configuring FortiNAC to work with RADIUS authentication, but I haven’t been able to find anywhere a complete list of available RADIUS attributes.
Additionally, when setting up devices for EAP-TLS authentication using certificates, I noticed that NAC allows the use of “pseudo-attributes” such as TLS-Client-Cert-Common-Name or TLS-Client-Cert-Subject-Alt-Name-UPN, and so on.
Is there a full list of all available attributes?
When I open the dropdown menu, it only shows the first 10 attributes starting with “A.”
If I type “TLS” and open the dropdown, it doesn’t show these pseudo-attributes either.
Any guidance on where to find a complete list of supported RADIUS and TLS pseudo-attributes would be greatly appreciated.
Thank you!
Are you referring to the RADIUS attributes that are configured in the User/Host Profile or you want to customize the RADIUS attributes that are used for the authentication?
In the UHP, the output is limited to 10 entries for ease of use. To facilitate the configuration and to verify host matching accuracy, you can refer to Endpoint Fingerprints details for the relevant hosts:
A complete list of RADIUS attributes and authentication customization options can be found under Network > RADIUS [Attribute Groups].
User | Count |
---|---|
2587 | |
1380 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.