question

phantomscribe avatar image
0 Likes"
phantomscribe asked

RADIUS authentication group matching not working

I've created a RADIUS server and the test connection shows successful. However, when I create a user group and add the remote server, then create a group, my users never match that group. If I don't add a group name, then users match correctly (as expected). What am I doing wrong?
FortiOSRADIUS
10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

1 Answer

·
Tomcat Silver avatar image
0 Likes"
Tomcat Silver answered

Not completely clear what you have set, no CLI snippets or config attached or any debug outputs her. And especially last sentence is misleading me a bit.

However some years ago I have posted this KB to clarify how the RADIUS Group Match (as it is usually referenced as) works on FortiOS.

KEY part is the RADIUS server configuration as FortiGate's config of 'set group-name' ...

Like in example:

# config user group
edit "GROUP_RAD"
  set member "RAD"
  config match
    edit 1
      set server-name "RAD"
      set group-name "GRP-one"
    next
   end
   next
end

.. HAVE TO match to what RADIUS server sends as AVP 'Fortinet-Group-Name' in Access-Accept.
That is critical and the only linking point between what's on server and what's on FortiGate.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Authentication-Remote-server-group-match-of-user/ta-p/190905?cmd=displayKC&docType=kc&externalId=FD36464

10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Welcome to FortiAnswers

FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.

  • Please review the Community guidelines
  • If you are a moderator, please refer to the Moderation guidelines
  • If something in the above guidelines is unclear, please post your question to the Community Feedback space or the Moderators' space