Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

admins auth via radius (MS IAS)

Hi All, Did anyone managed to configure admin authorization from Radius server (MS IAS). I' ve got to a stage where Windows is showing that user has been authorized but FGT still doesn' t let me in. VSA in IAS is set like this: Vendor-Code: 12356 Vendor assigned attribute number: 1 Attribute format: String Value: prof_admin Debug in the CLI (diag deb appl fnbamd 255) is showing following: fnbamd_fsm.c[886] handle_req-Rcvd auth req 2883595 for adm in ADMINS_IAS opt=1 prot=8 fnbamd_radius.c[780] fnbamd_radius_auth_send-Sent radius req to 10.0.0.1: code=1 id=34 len=155 user=" adm" using MS-CHAPv2 fnbamd_auth.c[544] auth_tac_plus_start-Didn' t find tac_plus servers (0) fnbamd_auth.c[292] ldap_start-Didn' t find ldap servers (0) fnbamd_radius.c[980] fnbamd_radius_auth_validate_pkt-Invalid digest fnbamd_auth.c[1240] fnbamd_auth_handle_result-Error validating radius rsp fnbamd_fsm.c[1068] handle_auth_rsp-Error (5) for req 2883595 fnbamd_fsm.c[1134] handle_auth_timeout_with_retry-Session timeout, retry fnbamd_auth.c[205] radius_start-Didn' t find radius servers (0) fnbamd_fsm.c[1145] handle_auth_timeout_with_retry-retry failed fnbamd_fsm.c[1177] handle_auth_timeout_without_retry-Session expired fnbamd_comm.c[104] fnbamd_comm_send_result-Sending result 3 for req 2883595 IAS is showing that user has been granted access. My assumption is that either FGT doesn' t like self-signed cert for MS-CHAPv2 on the radius or the parameters inside IAS are wrong. Please help. Marko
12 REPLIES 12
abelio

Hello, there' re new things for MR7 in this article: http://kc.forticare.com/redirfile.asp?id=2278 regards

regards




/ Abel

regards / Abel
40net
New Contributor

Hey Marko Did you find any solution to that ? I am having the same issue ...
iFortify
New Contributor

For information on configuring administrative access with Radius Authentication, please refer to the MR7 Administration Guide starting on page 198
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors