Hello Guys,
I wan to enforce web user authentication against Fortinac local database.
I have added a Fortiswitch working in standalone mode.
I did set both registration and authentication to enforce.
created a local user and set role to "test-role"
added the switch port to the forced registration and forced authentication and role based access group.
manually registered my laptop to the "test-role"
created an authentication policy matching on a user-host profile matching on :
where: any
who what by group : any
who what by attribute : host [role:test-role]
Then a network access policy matching on the following profile:
where: any
who what by group : any
who what by attribute : host [role:test-role] user [role:test-role]
Results:
I am successfully switched to the authentication vlan got the correct ip address, redirected to the authentication portal but when I enter my local credentials: I get the following on the portal:
authentication failed, please try again.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You can check on Portal> Portal Configuration> Global [Settings] for the option "Standard User Login Type" that will handle the registration part. For guest solution only the self registration is commonly used, no authentication is needed.
If you still need the Authentication step you have to add a configuration for the policy where this user hits and choose Local as authentication method:
Hi Ebilcari,
I have already done the authentication policy part. Actually I am only transited to the authentication VLAN after I did this step.
Verified the standard user login to be local in the poral configuration and also in the authentication configuration applied to the auth policy.
more information can be checked using the CLI while enabling this debug:
> nacdebug -name DirectoryAuthentication true
> logs
> tf output.master
if the output is overwhelming you can add the grep command [| grep username]
Hi Akmostafa,
Dont forget to disable debug using following command:
>nacdebug -name DirectoryAuthentication false
BR
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.