This article covers configuration of Fortigate devices for use with ºÚÁϺ£½Ç91Èë¿Ú’s RADIUS Servers. Once configured, users connecting through your Fortigate VPN or networking device can authenticate via RADIUS with their ºÚÁϺ£½Ç91Èë¿Ú credentials.
This configuration applies to most Fortigate devices, but screenshots and locations of these settings within the Fortigate systems may vary with newer updates from the vendor.
Prerequisites:
- A ºÚÁϺ£½Ç91Èë¿Ú RADIUS server IP address is required to configure a Fortigate device.
- You also need the shared secret that’s part of a ºÚÁϺ£½Ç91Èë¿Ú RADIUS server configuration.
- To find the shared secret:
- Go to the .
- Select USER AUTHENTICATION > RADIUS from the left-hand navigation.
- Select a configured RADIUS server. The Shared Secret is below Server Name.
- Click the eye to make the characters visible, then copy the shared secret to use in the Fortigate configuration.
- To find the shared secret:
To configure a Fortigate device to use ºÚÁϺ£½Ç91Èë¿Ú RADIUS:
- Log in to your Fortigate Admin Panel with your Administrator credentials.
- In the left menu, go to User & Authentication > RADIUS Servers.
- These are the settings that need to be configured to point to ºÚÁϺ£½Ç91Èë¿Ú’s RADIUS Servers.
- These are the settings that need to be configured to point to ºÚÁϺ£½Ç91Èë¿Ú’s RADIUS Servers.
- Under Edit RADIUS Server, enter the following settings:
- Name: ºÚÁϺ£½Ç91Èë¿Ú RADIUS Server
- Authentication Method: Specify
- Select the RADIUS Protocol that fits your needs. Learn more around supported RADIUS Authentication Protocols and ºÚÁϺ£½Ç91Èë¿Ú.
- NAS IP: Enter if applicable.
- Next, configure the Primary Server:
- IP/Name: Enter in the IP Address for the ºÚÁϺ£½Ç91Èë¿Ú RADIUS Server closest to your geographic region.
- Secret: This is the RADIUS Secret you’ve configured within your ºÚÁϺ£½Ç91Èë¿Ú Admin Portal.
If Test Connectivity fails after copying / pasting the Shared Secret from the ºÚÁϺ£½Ç91Èë¿Ú Admin Portal, try entering it manually.
- Repeat the previous step for the Secondary Server using a different RADIUS Server.
- For example, if you used 18.204.0.31 (US East) for your Primary Server, you'll want to set up 54.203.27.225 (US West) for your Secondary Server. This will ensure a level of fault tolerance if there are issues with connections to the primary server.
- Next, click Test Connectivity for both the Primary and Secondary Servers.
- If an error occurs, verify the configuration performed in the previous steps.
- Finally, click Test User Credentials and enter the credentials of your ºÚÁϺ£½Ç91Èë¿Ú test account.
- If an error occurs testing user credentials:
- Ensure the password of the ºÚÁϺ£½Ç91Èë¿Ú user is entered correctly.
- Ensure the username of the ºÚÁϺ£½Ç91Èë¿Ú user is entered correctly.
- Verify the test user is associated with the RADIUS Server you configured within the ºÚÁϺ£½Ç91Èë¿Ú Admin Portal. See Selecting Users for Access to the RADIUS Server.
- If an error occurs testing user credentials: