Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nick_Mavrou
New Contributor

Fortigate and Cisco ISE User based policy

Hi Guys,

 

I have an implantation which requires the fortigate to recognize a user when it is connecting to WiFi over dot1x. The radius server is Cisco ISE and the external ID I am using is an MS Active Directory. The whole communication between the client and the Cisco ISE happens over certificates, so all good here. Is it any way the fortigate to be able to see that and then perform a firewall policy based on user?

 

Many Thanks 

1 REPLY 1
distillednetwork
Contributor III

You could look at sending Radius accounting messages from the ISE server to the fortigate using RSSO.  When enabled, you will be able to send radius attributes based on user details in ISE and match them to a group in Fortigate.

 

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/85730/radius-single-sign-on-rsso-agent

 

If you have a large number of users connecting to the wifi, I would suggest using an FSSO server and send the radius messages to that instead of the fortigate direct.  This will greatly reduce the load on the Fortigate.  This article will show at the bottom how you can enable Radius accouting in the FSSO agent and then link the fortigate to the FSSO server to get the details:

 

https://community.fortinet.com/t5/Fortinet-Forum/Fortigate-Combining-RSSO-and-FSSO/m-p/219887

 

Hope that helps!

 

Labels
Top Kudoed Authors