FortiManager 7.2.1 RADIUS Configuration - RSA Ready Implementation Guide
Originally Published: 2023-03-24
This section describes how to integrate FortiManager with RSA Cloud Authentication Service using RADIUS.
Procedure
- Sign into the FortiManager GUI and use the correct ADOM according to your company to be able to access the System Settings.
- On the left pane, select Admin, then select Remote Authentication Server from the drop down. Select Create New and click on RADIUS Server.
- Enter the name of the RADIUS server as per your needs and fill in the following details:
- Enter the IP address/FQDN details from the RSA Identity Router management IP in Server Name/IP field and enter the shared secret.
- Configure a Secondary RADIUS Server if needed.
- Select PAP as the Authentication Type.
- On the left pane, under Admin, select Administrator to choose who is prompted for RSA RADIUS authentication.
- Select Create New and enter the username in the User Name field.
- You can choose an admin username, or you can choose to authenticate all admins by selecting Match all users on the remote server checkbox.
- Select RADIUS from the Admin Type dropdown, and then select the RADIUS server created in step 3.
- Sign into the RSA Cloud Console and go to Authentication Clients > RADIUS > Add RADIUS Client and Profiles.
- To validate the LDAP password, apply the access policy that includes MFA to input your SecurID OTP/Authenticate OTP/Biometrics/Approve/SMS/Voice OTP or directly apply the access policy.
- Choose access policy that suits your needs that is created from Access > Policies and then select Save and Next Step.
- Create a RADIUS profile to return a certain RADIUS attribute back to the FortiManager, like Fortinet-Access-Profile, to return a profile created on the FortiManager for authorization, like Restricted_User.
- You can apply the profile back to the FortiManager, as it rejects any profile override by default. To do this, go to the FortiManager through CLI and perform the following commands under the needed Access Profile:
- Select Finish and then Publish Changes.
Configuration is complete.
Return to the main page.
Related Articles
Okta Agent - RADIUS Configuration - Authentication Manager - RSA Ready Implementation Guide 119Number of Views Okta Agent - RADIUS Configuration - Cloud Authentication Service - RSA Ready Implementation Guide 186Number of Views SonicWall SonicOS - RADIUS Configuration for Cloud Authentication Service - RSA Ready Implementation Guide 40Number of Views Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 672Number of Views FortiGate Firewall - RADIUS Configuration Using Admin Access UI - RSA Ready Implementation Guide 79Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to replace the RSA Authentication Manager self signed console certificate with a signed certificate from Microsoft Act… RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to Request Access to the RSA Authentication Manager AMI for AWS via RSA Support
Don't see what you're looking for?