Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Alienated
New Contributor

Fortigate 300D 5.6.0 > 5.6.3

I am looking to upgrade the firmware on my 300D and have been reading through the release notes. There is one section I am hoping to get some clarification on.

 

Under the Upgrade Information section there is a little note:

 

After upgrading, if FortiLink mode is enabled, you must manually create an explicit firewall policy to allow RADIUS traffic for 802.1x authentication from the FortiSwitch (such as from the FortiLink interface) to the RADIUS server through the FortiGate.

 

I have fortilink mode enabled but I haven't configured any 802.1x settings at all. We have a FortiAuthenticator that we use for SSL-VPN but otherwise I don't believe we are using the RADIUS server for anything else.

 

Has anyone else had issues with the upgrade in regards to these settings? What did you have to do and what did your policy look like.

 

Any help or advice would be greatly appreciated.

 

Our network is fairly small, only about 100 users with around 8 switches.

1 REPLY 1
ericli_FTNT
Staff
Staff

BBOUCHER wrote:

I am looking to upgrade the firmware on my 300D and have been reading through the release notes. There is one section I am hoping to get some clarification on.

 

Under the Upgrade Information section there is a little note:

 

After upgrading, if FortiLink mode is enabled, you must manually create an explicit firewall policy to allow RADIUS traffic for 802.1x authentication from the FortiSwitch (such as from the FortiLink interface) to the RADIUS server through the FortiGate.

 

I have fortilink mode enabled but I haven't configured any 802.1x settings at all. We have a FortiAuthenticator that we use for SSL-VPN but otherwise I don't believe we are using the RADIUS server for anything else.

 

Has anyone else had issues with the upgrade in regards to these settings? What did you have to do and what did your policy look like.

 

Any help or advice would be greatly appreciated.

 

Our network is fairly small, only about 100 users with around 8 switches.

Hi there,

 

The potential reason of that issue is because FortiAuthenticator is moving down to FSW. So for allowing traffic passing from fortilink to the gateway port of the FGT, you would need to configure an explicit firewall policy from the fortilink interface, to allow Radius traffic.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors