Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jim_FH
New Contributor III

Forticlient RADIUS server authentication - user groups

Kind of a strange question:

I have two RADIUS servers, and two different user groups defined - one per RADIUS server.

 

I'm wondering if there's a way to prioritize authenticating against one RADIUS server over the other.

 

So, we have a user connect via Forticlient, and authenticate against RADIUS Server1, which puts him/her in Group1. If Server1 is down, then it would authenticate against the Server2 and put the user in a differnt group.

 

I thought I could achieve the desired result via the policies - put the user group from Server1 in a policy above a policy that refers to the user group from Server2, but it seems like authentication is happening round-robin across the RADIUS servers, so it's impossible to predict which server will authenticate.

 

Any ideas how to prefer one over the other?

11 REPLIES 11
Paul_Fo

So I have some confusion about the group attribute.  Am I adding the attribute that is the same as the one created on the fortigate or the one that matches the AD group on the NPS?

Paul_Fo

I had help figuring this out.  It seems the radius timeout has to be set greater than 5 seconds.  It is set to 150 and everything works.  Thank you for your assistance.

 

Labels
Top Kudoed Authors