Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TJay
New Contributor

Syslog to FSSO

I have issue with configuring Forti authenticator to get the authentication information from CISCO ACS which will authenticate wireless users . I Have configure the Authenticator and I can see the traffic going from ACS to Authenticator But I'm unable to see the information from Authenticator. I have refer to the Authenticator admin guide to set this up but seems to be not working so far.

 

 

 

1 Solution
xsilver_FTNT
Staff
Staff

What is the role of FortiAuthenticator , what do you want to achieve by this ?

Is it:

- RADIUS server for the Cisco ?

- gathering RADIUS Accounting from WiFi controller and does RSSO for FortiGate ?

- doing something totally different ?

 

More info needed, or maybe consider to either contact Fortinet SE or Partner for advise with config or open a ticket with Fortinet Support.

 

regards, Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

View solution in original post

4 REPLIES 4
xsilver_FTNT
Staff
Staff

What is the role of FortiAuthenticator , what do you want to achieve by this ?

Is it:

- RADIUS server for the Cisco ?

- gathering RADIUS Accounting from WiFi controller and does RSSO for FortiGate ?

- doing something totally different ?

 

More info needed, or maybe consider to either contact Fortinet SE or Partner for advise with config or open a ticket with Fortinet Support.

 

regards, Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

TJay

forti authenticator works for SSO for LAN users Im using AD polling mode.

But for Wireless users they are authenticated through Cisco ACS,Basically ACS  send authentication infor to  Controllers for BYOD staff users. What I need to work SSO for BYOD staff users 

Carl_Windsor_FTNT

TJay wrote:

Basically ACS  send authentication infor to  Controllers for BYOD staff users. What I need to work SSO for BYOD staff users 

You don't explain how you have configured ACS to send the authentication info to FAC.  RADIUS Accounting, SYSLOG?  Whichever it is, you have to configure the relevant collector to parse the information and inject into FSSO.  Provide some more detail and perhaps screenshots of your config and we can endeavor to help.

 

Dr. Carl Windsor Field Chief Technology Officer Fortinet

TJay

I have configure Cisco ACS to send Syslog  to the Forti Authenticator.

Authenticator I have configure Fortinet SSO Methods > SSO > Syslog  create a new matching rule by giving Cisco ACS IP ADDress

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors