matanaskovic
Staff
Created on
12-05-2017
07:37 PM
Edited on
03-10-2025
12:19 AM
By
Anthony_E
Article Id
198422
Description | This article describes how to configure the SSL VPN Web Portal on FortiGate to assign a fixed IP address with FortiAuthenticator as a RADIUS server for the users. |
Scope | FortiAuthenticator. |
Solution |
FortiGate Configuration. Edit Web Portal configured for fixed IPs and set 'ip-mode' to 'user-group'. Once configured, all users in the authentication group must have an assigned IP otherwise authentication will fail:
config vpn ssl settings
set servercert "Fortinet_Factory" set tunnel-ip-pools "SSLVPN_TUNNEL_ADDR1" set tunnel-ipv6-pools "SSLVPN_TUNNEL_IPv6_ADDR1" set source-interface "port1" set source-address "all" set source-address6 "all" set default-portal "web-access" config authentication-rule
edit 1 set groups "framed_ip_grp2" "framed_ip_grp1" set portal "test_FixIP" next end end
config vpn ssl web portal edit "test_FixIP" set tunnel-mode enable set ip-mode user-group <----- Default paramter: range. set ip-pools "Range_Fix_IP" <----- IP range. next config firewall policy FortiAuthenticator Radius Configuration.
Vendor: Default.
Related article: Technical Tip: Radius authentication with FortiAuthenticator |