Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FXD
New Contributor

Per-ADOM admin profile with Cisco ISE Tacacs

Hi, 

I have a FortiManager running 7.4 with three ADOMs. I am using tacacs+ wildcard authentication with accprofile override using Cisco ISE as authentication server. All administrators authentication get Read_Write profile for all ADOMs. 

I would like to use the feature per-ADOM admin profile as described in this article to give administrators belonging to "Group1" to get Read_Write for one of the ADOMs and Read_Only for all of the others. From the article above this seems possible with ext-auth-adom-override enabled. However, I am not sure how this would be configured on the tacacs server as that is not covered in the article.

Today I send the following attributes from TACACS server:
service=fortigate

admin_prof=Read_Write

adom=Adom1

adom=Adom2

adom=Adom3.

 

How should I configure the tacacs server to send Read_Write for Adom1 and Read_Only for Adom2 and Adom3?

2 REPLIES 2
asrour
Staff
Staff

hi @FXD 

check this article:

Configure RADIUS for authentication and a... - Fortinet Community

Thanks

 

A Srour
FXD
New Contributor

Hi @asrour 

I have read the article, which covers radius, but the examples are only showing how to give the same access profile to all of the ADOMs. I am trying to figure out how to give users in "Group1" read-write to ADOM1 and read-only to ADOM2 & ADOM3.

Going back to the article I found and linked in my previous post this seems possible, in that example users get Profile1 to ADOM1 and Profile2 to ADOM2.


Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors