Hi,
If there is an external firewall between the Radius server(which is outside my network) and my Fortigate as the radius client, then I need to have a rule on the external firewall to allow RADIUS traffic from my Fortigate firewall. so the source address on the rule should be teh address of RADIUS client which is my Fortigate. My question is what address do I have to use ? would it be the outside interface of my Fortigate?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Most likely yes. You can do a diag sniffer packet any "port 1812" for example to see the src.ip
Ken Felix
PCNSE
NSE
StrongSwan
In general outgoing services from a FGT default to the outgoing interface IP.
For many of these services the IP can be changed (eg to a loopback IP). This can be done for ntp, snmp, syslog at least.
This looks to be applicable to radius as well:
config user radius
edit test
set source-ip 1.1.1.1
next
endI'm not sure if this is the correct radius configuration for what you are doing but this may suit your needs.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.