Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
shane_caznet
New Contributor

IPv6 users not authenticated by RSSO and FSSO

Hi

 

We have 2 Fortigate 300D running FortiOS 5.4.7 in a HA A-A cluster.

 

Our users are authenticated to our Fortigates by 2 ways: 1) FSSO using the Active Directory collector agent for domain joined machines, and 2) RSSO using Radius Accounting from our wireless (Ubiquiti) to Microsoft NPS Radius for non-domain joined BYOD devices such as iPads.

 

Our users show as authenticated with IPv4 sessions (user to IP address) as expected for both authentication types. However, we do not see any authenticated users with IPv6 addresses. When users access the internet using an IPv6 address, they get our unauthenticated user policy.

 

I'm not sure what I need to change to get both the IPv4 and IPv6 authentication for every user. Does Fortigate support dual-stack for user auth in this scenario? Am I missing something?

 

Shane

6 REPLIES 6
xsilver_FTNT
Staff
Staff

Hi Shane,

 

there is no GA release supporting IPv6 in FSSO as of now.

See "FSSO does not currently support IPv6." in FortiOS Release Notes page 14 'Fortinet Single Sign-On' section in integration support part.

https://docs.fortinet.com/uploaded/files/4088/fortios-v5.6.3-release-notes.pdf

 

There is IPv6 support in RADIUS Accounting (RSSO) on FortiOS.

If you send Framed-IPv6-Address then FortiGate will process it.

Example:

----------

# sent data via radclient (Freradius-utils)

root@SRV-DEB-1:~# echo "Acct-Status-Type = Start, User-Name = JohnDoe , Class = ClassProfile , Framed-IPv6-Address = 2001:db8:0:69a1::1" | radclient -4 -c 1 -n 1 -x 192.168.32.251:1813 acct fortinet Sending Accounting-Request of id 19 to 192.168.32.251 port 1813 Acct-Status-Type = Start User-Name = "JohnDoe" Class = 0x436c61737350726f66696c65 Framed-IPv6-Address = 2001:db8:0:69a1::1

# result in debug app radiusd -1

FGVM_251 # Received radius accounting eventvd 0:root Add/Update auth logon for IP 2001:db8:0:69a1::1 for user (null) DB 0 insert [ep='n/a' pg='ClassProfile' ip='2001:db8:0:69a1::1'] success

# result in DB

FGVM_251 # diagnose test application radiusd 33 RADIUS server database [vd root]: "index","start time","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile" 1,1516088594,07:59:37,"2001:db8:0:69a1::1","","n/a","n/a","<default profile>",0,Yes Best regards,

Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

sviusa

Hello,

 

I'm in the same config as yours. trying to make the same exact thing. for now no way.

I've tried to make the machine IPv6 only and the log on fortigate shows :

 

RADIUS server database [vd root]: "index","start time","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile" 1,1533749461,00:00:00,"::/32""LABUSER1","allow","no log","A12-RUN+]L",1,No 2,1533805132,00:00:00,"192.168.10.166""LABUSER2","allow","no log","A12-RUN+]�",1,No

 

Seams that the AP is not forwarding the framed-IPv6-Address...

 

is there any other means to achieve this ? maybe using Forticlient ?

 

thanks,

 

Regards,

 

 

Jeff_FTNT

FOS 6.0 support ipv6 FSSO.

 

IPv6 support for FSSO (1) connecting FSSO agent over IPv6; (2) accepting and applying IPv6 FSSO logons for IPv6 firewall policies.

sviusa

Hi All,

 

We have planned to move to fortios 6.0.2 on our validation environment this week-end.

@Jeff, is there any special thing to know for FSSO implementation under this os release ? Specific configuration on AD agent ? i don't have seen updated documentation so far.

 

Keep posted.

 

Regards,

 

Stephane

Jeff_FTNT

IPv6 FSSO need FSSO Agent support IPv6 too. May be FSSO Agent is not released.

sviusa

Hello,

 

I have made the test and logon under IPv6 are not monitored by the FSSO agent on AD.

I will wait for the new agent to continue the POC.

Also, i don't think that my Fortigate talks to FSSO agent under IPv6 event after setting the sourceIP6 in conf.

 

Thanks for your support guys,

 

Regards,

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors