This section describes how to integrate FortiGate Remote Access SSL VPN with RSA Authentication Manager using RADIUS.
Configure RSA Authentication Manager
Perform these steps to configure RSA Authentication Manager.
Procedure
- Log in to the RSA Authentication Manager.
- Go to Security Console > RADIUS > RADIUS Clients, and click Add New.
- In the Model section, select Fortinet.
Note: The Model section can remain set to Standard RADIUS if Fortinet RADIUS attributes are not required. However, if these attributes are needed, set the model to Fortinet to enable their use in the RADIUS profile later.
- Click Save & Create Associated RSA Agent > Save > Yes, Save Agent.
Configuration is complete.
Configure FortiGate Access SSL VPN using RADIUS
Perform these steps to configure RSA Authentication Manager Service using RADIUS.
Procedure
- Go to Admin UI of FortiGate > Users & Authentication > RADIUS Servers > New.
- Enter the IP of the RSA Authentication Manager or if you are using Cloud Authentication put the RSA Identity Router Management IP and shared secret.
Note: You can enter up to three servers if you have replicas or 3 identity routers, the second server can be configured via GUI, the tertiary one must be configured from CLI only. configure a tertiary server in the following format.
-
- FEIRDUFG02 # config user radius
- FEIRDUFG02 (radius) # edit RSA-AM
- FEIRDUFG02 (RSA-AM) # set tertiary-server 10.65.65.50
- FEIRDUFG02 (RSA-AM) # set tertiary-secret support1!
- FEIRDUFG02 (RSA-AM) # end
- Go to VPN > SSL VPN Settings.
- In the Authentication/Portal Mapping, select the User Groups configured for RSA Authentication Manager or RSA Cloud Authentication Service.
- Map the required portal (Full Access/Web Access/Tunnel Access) to the RSA User group to authenticate the user against RSA Server using RADIUS.
- In the Policy for the SSL VPN Access. Go to Policy & Objects, and select the IPV4 Policy for the SSL VPN.
- Configure the Source User to be the RSA User Group.
Notes:
- Refer to this section to configure the RADIUS Timeout.
- Refer to this section for the RADIUS return attributes.
Configuration is complete.
Related Articles
FortiGate Firewall - RADIUS Configuration Using SSL VPN - RSA Ready Implementation Guide 106Number of Views FortiGate Firewall - SAML Relying Party Configuration Using SSL VPN - RSA Ready Implementation Guide 63Number of Views RADIUS shared secret limitations of RADIUS clients configured with RSA Authentication Manager 759Number of Views FortiGate Firewall - RSA Ready Implementation Guide 256Number of Views FortiGate Firewall - SAML IDR SSO Configuration Using SSL VPN - RSA Ready Implementation Guide 52Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide