Creating a RADIUS policy
A RADIUS policy must be configured in order to allow RADIUS authentication for the selected client.
To create a RADIUS policy:
- Go to Authentication > RADIUS Service > Policies, and click Create New.
- Under RADIUS clients, configure the following, and click Next.
- Policy name: Enter a name for this policy, for example: FGT-Computer-TLS.
- RADIUS clients: Add the previously configured FortiGate RADIUS client to the Chosen RADIUS Clients section.
- Under RADIUS attribute criteria, click Next.
- Under Authentication type, choose Client Certificates (EAP-TLS), and click Next.
- Under Identity source, configure the following, and click Next.
- Username format: Select your preferred username format, for example: realm\username.
- Realms: In the Realms table, select your AD realm.
You can additionally apply a group filter if required.
- Under Authentication factors, click Next.
- Under RADIUS response, click Save and exit.