Hello everybody,
I have upgraded my FGT60F today from 7.2.6 to 7.2.9 and then to 7.2.10
This has been working fine without any issue.
After a while I noticed, that the VPN-Clients were not able to connect anymore.
When I inspected the Radius Server Connection (freeradius), it says:
Connection status: credentials not valid
I tried a few settings, whether I will get the connection back - but this did not work.
After changing back to 7.2.9 the connection with the radius server worked again.
Any ideas, what the problem could be?
Thanks,
Martin
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Martin
This is due to a new RADIUS vulnerability.
https://www.fortiguard.com/psirt/FG-IR-24-255
If I'm not wrong the solution is to use RADSEC.
Additionally you may check this:
Thanks for your quick answer!
Martin
Hold on. I had the opposite experience, it didn't work when FGT was 7.2.9 and the freeRADIUS was upgraded to the latest. So I had to exempt the FGT from Message-Authenticator attribute check as I posted before.
https://community.fortinet.com/t5/Support-Forum/RADIUS-attribute-Message-Authenticator/td-p/327120
So do you have this "require_message_authenticator = no" flag set? I would assume it would still work with 7.2.10 with this exception. Or you might need to upgrade the freeRADIUS to the latest.
Toshi
But your error is different from my case. Does it fail if you create a new user/set a new credential and try connecting VPN? Run "radiusd -X" to check the detail when it fails.
Toshi
Hi, please make sure your free radius is one of this version 3.0.26, 3.2.3, 3.2.5, 3.2.6. as these are working with FortiGate
By the way, mine is 3.0.25 and working fine with 7.2.10.
Toshi
Hi Toshi, Rahman
Does it mean RADSEC is not mandatory?
RADSEC is to just encrypt/encapsulate RADIUS UDP traffic in TLS, which is not available with 7.2.x anyway. As long as the server side can handle/reply FGT's auth request message with Message-Authenticator attribute, which most recent/decent servers do, it should work fine.
Or, RADSEC is more to address the security issue if the unencrypted RADIUS traffic goes over the internet.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1665 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.