Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
braddavisgwh
New Contributor II

NAT Query on fortiauthenticator cloud - radius

 

Hi all,

 

In the process of setting up FAC Cloud with radsec and a fortigate firewall - we are seeing the traffic coming to the FAC from a different IP to what is our FWs public IP address - when setting our radius client, this took me a little while to find. 

 

Can anyone advise what should be set under the client IP for radius, or how the traffic is handled please?

 

5 REPLIES 5
Jean-Philippe_P
Moderator
Moderator

Hello braddavisgwh, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Regards,
Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Regards,
Jean-Philippe - Fortinet Community Team
AEK
SuperUser
SuperUser

Hi Brad

When configuring the RADIUS client in FAC, the client IP should be the source IP, i.e. the public IP used by the device as source when sending the RADIUS request.

AEK
AEK
AEK

Indeed in case there is NAT device in front of your FGT then you will see the public IP of that NAT device.

AEK
AEK
braddavisgwh
New Contributor II

Hi - Yeah we had this setup like this originally but it was not working, a little digging and we I found some logs with a different IP address in fortiauthenticator cloud with a private address range 10.103.195.0/24 - the radius connection worked once assigning this as a client. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors