Hi
We have 2 Fortigate 300D running FortiOS 5.4.7 in a HA A-A cluster.
Our users are authenticated to our Fortigates by 2 ways: 1) FSSO using the Active Directory collector agent for domain joined machines, and 2) RSSO using Radius Accounting from our wireless (Ubiquiti) to Microsoft NPS Radius for non-domain joined BYOD devices such as iPads.
Our users show as authenticated with IPv4 sessions (user to IP address) as expected for both authentication types. However, we do not see any authenticated users with IPv6 addresses. When users access the internet using an IPv6 address, they get our unauthenticated user policy.
I'm not sure what I need to change to get both the IPv4 and IPv6 authentication for every user. Does Fortigate support dual-stack for user auth in this scenario? Am I missing something?
Shane
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Shane,
there is no GA release supporting IPv6 in FSSO as of now.
See "FSSO does not currently support IPv6." in FortiOS Release Notes page 14 'Fortinet Single Sign-On' section in integration support part.
https://docs.fortinet.com/uploaded/files/4088/fortios-v5.6.3-release-notes.pdf
There is IPv6 support in RADIUS Accounting (RSSO) on FortiOS.
If you send Framed-IPv6-Address then FortiGate will process it.
Example:
----------
# sent data via radclient (Freradius-utils)
root@SRV-DEB-1:~# echo "Acct-Status-Type = Start, User-Name = JohnDoe , Class = ClassProfile , Framed-IPv6-Address = 2001:db8:0:69a1::1" | radclient -4 -c 1 -n 1 -x 192.168.32.251:1813 acct fortinet Sending Accounting-Request of id 19 to 192.168.32.251 port 1813 Acct-Status-Type = Start User-Name = "JohnDoe" Class = 0x436c61737350726f66696c65 Framed-IPv6-Address = 2001:db8:0:69a1::1
# result in debug app radiusd -1
FGVM_251 # Received radius accounting eventvd 0:root Add/Update auth logon for IP 2001:db8:0:69a1::1 for user (null) DB 0 insert [ep='n/a' pg='ClassProfile' ip='2001:db8:0:69a1::1'] success
# result in DB
FGVM_251 # diagnose test application radiusd 33 RADIUS server database [vd root]: "index","start time","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile" 1,1516088594,07:59:37,"2001:db8:0:69a1::1","","n/a","n/a","<default profile>",0,Yes Best regards,
Tomas
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hello,
I'm in the same config as yours. trying to make the same exact thing. for now no way.
I've tried to make the machine IPv6 only and the log on fortigate shows :
RADIUS server database [vd root]: "index","start time","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile" 1,1533749461,00:00:00,"::/32""LABUSER1","allow","no log","A12-RUN+]L",1,No 2,1533805132,00:00:00,"192.168.10.166""LABUSER2","allow","no log","A12-RUN+]�",1,No
Seams that the AP is not forwarding the framed-IPv6-Address...
is there any other means to achieve this ? maybe using Forticlient ?
thanks,
Regards,
FOS 6.0 support ipv6 FSSO.
IPv6 support for FSSO (1) connecting FSSO agent over IPv6; (2) accepting and applying IPv6 FSSO logons for IPv6 firewall policies.
Hi All,
We have planned to move to fortios 6.0.2 on our validation environment this week-end.
@Jeff, is there any special thing to know for FSSO implementation under this os release ? Specific configuration on AD agent ? i don't have seen updated documentation so far.
Keep posted.
Regards,
Stephane
IPv6 FSSO need FSSO Agent support IPv6 too. May be FSSO Agent is not released.
Hello,
I have made the test and logon under IPv6 are not monitored by the FSSO agent on AD.
I will wait for the new agent to continue the POC.
Also, i don't think that my Fortigate talks to FSSO agent under IPv6 event after setting the sourceIP6 in conf.
Thanks for your support guys,
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1698 | |
1092 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.