Hi there,
I am currently using FortiAuthenticator as the TACACS+ sever for our enviornment. All of my admin users are imported via LDAP.
When I assign a TACACS Profile directly to the user, the user is able to successfully authenticate to devices.
If I remove the TACACS profile and assign the TACACS profile to a User Group that contains the User, the TACACS debug logs shows successful Authentication, but Authorization fails because TACACS reports that the user is not in a group which has a TACACS profile.
If I do the same thing with a Local Group that contains Local Users, the inheritance of TACACS Profile works just fine.
Has anyone else experienced this issue?
FAC version = v6.4.7, build1054 (GA)
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Please check the configuration as per the document below and let us know the status.
Regards
Jamal Hussain
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.