Configuring the FortiAuthenticator
To create the RADIUS client:
- On the FortiAuthenticator, go to Authentication > RADIUS Service > Clients, and select Create New.
- Enter a Name, the IP address of the FortiGate, and set a Secret.
The secret is a pre-shared secure password that the FortiGate will use to authenticate to the FortiAuthenticator.
To create the RADIUS policy:
- Go to Authentication > RADIUS Service > Policies, and select Create New.
- Enter the RADIUS policy name, description, and select the FortiGate RADIUS client.
- Do not configure RADIUS attribute criteria.
- Choose Password/OTP authentication as the authentication type and enable all EAP types.
- Choose a username format (in this example: username@realm), select the Local realm.
Add the employees user group as a filter. - Set the authentication method to Password only authentication.
- Review the RADIUS response, and click Save and Exit.
To create the local user accounts:
- Next go to Authentication > User Management > Local Users and create local user accounts as needed.
- For each user, add the following RADIUS attributes which specify the VLAN information to be sent to the FortiGate.
The Tunnel-Private-Group-Id attribute specifies the VLAN ID.
In this example, jsmith is assigned VLAN 100 and twhite is assigned VLAN 200.