Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AaronChih
New Contributor

[HELP] Authenticated TACACS+ first then local

Hi all,

If you can not understand what i'm saying,I apologize for my poor English.

 

I have a question in using TACACS+ . When TACACS+ server is active ,and my fortigate can reach the TACACS+ server.

Can I only let user login with tacacs+ account ,and failed when use local account?

And when fortigate can't reach TACACS+ server, user only can login with local account?

 

what should I configure to reach this goal?

I've study lot of web site but got no answer

 

My Fortigate is 1500D with version 5.0.14

2 REPLIES 2
michaelbazy_FTNT

Hi Aaron,

 

I don't think that you can specify a detection for TACACS status.

 

Therefore, you can't.

 

However, what I'd do would be, in case of a local authentication, to add 2-factor auth to limit the risk.

 

Cheers,

I'm operating by "Crocker's Rules"
AaronChih

Hi Mike,

Thanks for your kindly reply.

This question comes from my Customers,cause their other device (i.e.Router,Switch..) can Authenticated TACACS first. So they think Fortigate should be too.

If I enter account doesn't exist in TACACS but config in local,it will passed right?

Labels
Top Kudoed Authors