Created on 04-01-2009 03:03 AM
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 04-01-2009 09:54 AM
regards
/ Abel
Created on 04-01-2009 11:13 PM
Created on 04-02-2009 03:32 AM
Testing with freeRadius and NTTack shows that fortigate can' t do this. i hope Fortinet add this feature very soon.It' s not a fortigate task to do; all the double-auth check is done in radius server, so it' s a topic to solve from radius server side; i.e. Radiator server, from australian company Open, is a non-free radius server that can check multiple logins within RADIUS active users (non FGT) and block concurrent logins. It' s the radius server that deny the auth is the user is already in its table; there' s no ' disconnect' features (so you cannot disconnect an user issuing commands from radius server) and those things, because the FTG it' s not a network access server (nas) talking with radius server. Check within Fortinet docs for radius dictionary attributes available. There' re new ones with each firmware version. regards
regards
/ Abel
Created on 04-03-2009 01:41 AM
I doubt that v4 will have any pptp changes.agree; pptp is going to deprecated state with time (not only under FTG)
The way i see it is, the auth server is only contacted to authenticate the server. When they user logs off i do not think there is any mechanism for the fortinet to tell the auth server they have. hence it cannot track them. Thats how i see it, is that what you are saying abelio?Almost. Radius maintain its own table of authenticated users; there' s no a mechanism that allow radius to receive a notification from FTG when user disconnects. Radius server could detect detect a new access from that user and deny it if that user lives within authenticated usertable. So, under such limited scenario, is useless. However, another radius settings or conditions could you enable cleaning authenticated users from the table and make the scenari more usable.
regards
/ Abel
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.