Hi all,
If you can not understand what i'm saying,I apologize for my poor English.
I have a question in using TACACS+ . When TACACS+ server is active ,and my fortigate can reach the TACACS+ server.
Can I only let user login with tacacs+ account ,and failed when use local account?
And when fortigate can't reach TACACS+ server, user only can login with local account?
what should I configure to reach this goal?
I've study lot of web site but got no answer
My Fortigate is 1500D with version 5.0.14
Hi Aaron,
I don't think that you can specify a detection for TACACS status.
Therefore, you can't.
However, what I'd do would be, in case of a local authentication, to add 2-factor auth to limit the risk.
Cheers,
Hi Mike,
Thanks for your kindly reply.
This question comes from my Customers,cause their other device (i.e.Router,Switch..) can Authenticated TACACS first. So they think Fortigate should be too.
If I enter account doesn't exist in TACACS but config in local,it will passed right?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1112 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.