Announcements

SecurID® Discussions

Browse the SecurID discussion board to get product help and collaborate with other SecurID users.
KevinCulpepper
Beginner
Beginner

How do I changeover to a new Fortinet firewall and still have my tokens working?

Jump to solution

We presently are using SecureID hardware tokens in conjunction with a Checkpoint firewall and Authentication Manager 6.1. We have changed our firewall to Fortigate 300D so we are now looking to use these same tokens with this new firewall. Where can I find  documentation on getting this set up with the latest Authentication Manager software and having the tokens not tied to the old version of the software anymore?

Labels (1)
0 Likes
1 Solution

Accepted Solutions
JayGuillette
Apprised Contributor Apprised Contributor
Apprised Contributor

The Implementation Guide is at the bottom of the page Ed posted, which I found by searching Link for Fortigate Authentication at the top level of Link, searching from down in a product is not as reliable per design I think.  It explains that a Foritgate will be a RADIUS Client (with associated Auth Agent) on the AM server.  Concept same in AM 6.1, but console looks very different if you have not upgraded from ACE 6.1 yet.  You can leave the old Checkpoint agent entry, or delete it if you are sure no one will want to use it again.

In AM 6.1, you have to use Remote Admin - RADIUS - Manage RADIUS (I I remember correctly), which should bring up an interface to SBR RADIUS

ACE61_RADIUS_Client.png

View solution in original post

2 Replies
EdwardDavis
Employee
Employee

Here you can download a Setup/Implementation guide for Fortigate and RSA server v8.x

 

Fortinet FortiGate 

JayGuillette
Apprised Contributor Apprised Contributor
Apprised Contributor

The Implementation Guide is at the bottom of the page Ed posted, which I found by searching Link for Fortigate Authentication at the top level of Link, searching from down in a product is not as reliable per design I think.  It explains that a Foritgate will be a RADIUS Client (with associated Auth Agent) on the AM server.  Concept same in AM 6.1, but console looks very different if you have not upgraded from ACE 6.1 yet.  You can leave the old Checkpoint agent entry, or delete it if you are sure no one will want to use it again.

In AM 6.1, you have to use Remote Admin - RADIUS - Manage RADIUS (I I remember correctly), which should bring up an interface to SBR RADIUS

ACE61_RADIUS_Client.png