Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
WANAccounts
New Contributor II

TACACS+ Not Reading User Group for Remote Users

Hi there,

I am currently using FortiAuthenticator as the TACACS+ sever for our enviornment. All of my admin users are imported via LDAP.

When I assign a TACACS Profile directly to the user, the user is able to successfully authenticate to devices. 
If I remove the TACACS profile and assign the TACACS profile to a User Group that contains the User, the TACACS debug logs shows successful Authentication, but Authorization fails because TACACS reports that the user is not in a group which has a TACACS profile.

If I do the same thing with a Local Group that contains Local Users, the inheritance of TACACS Profile works just fine.

Has anyone else experienced this issue?

FAC version = v6.4.7, build1054 (GA)

1 REPLY 1
jhussain_FTNT

Hi,

 

Please check the configuration as per the document below and let us know the status.

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-FortiAuthenticator-as-TACACS-serv...

 

Regards

Jamal Hussain

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors