Fortinet white logo
Fortinet white logo

User Guide

RADIUS

RADIUS

RADIUS authentication allows FortiGuest to authenticate users using their existing RADIUS user accounts.

  • Support eduroam - Enable/disable Eduroam support with the RADIUS server. See Adding RADIUS and RadSec for Eduroam.
  • Server IP Address - The IP address of the RADIUS server.
  • Authentication Port - The authentication port number of the RADIUS server.
  • Secret - The shared secret for the RADIUS client. This must match the shared secret specified in the configuration of the RADIUS client.
  • Message-Authenticator attribute - You can enable/disable sending the message authenticator attribute to the server when configuring the RADIUS client.

Configure the User, that is, the realm/domain to which the user belongs. This option is not available if eduroam support is enabled. You can enable SSID mapping and add the SSIDs that will use the configured authentication policy, if there is no realm in the RADIUS request. Ensure that the Called-Station-ID attribute contains the SSID as part of the authentication request.

Enter any Attribute Mappings required for the server and then map them to the usage profile you require and also set the account group. Click Add Mapping to configure the rules for the policy.

RADIUS

RADIUS

RADIUS authentication allows FortiGuest to authenticate users using their existing RADIUS user accounts.

  • Support eduroam - Enable/disable Eduroam support with the RADIUS server. See Adding RADIUS and RadSec for Eduroam.
  • Server IP Address - The IP address of the RADIUS server.
  • Authentication Port - The authentication port number of the RADIUS server.
  • Secret - The shared secret for the RADIUS client. This must match the shared secret specified in the configuration of the RADIUS client.
  • Message-Authenticator attribute - You can enable/disable sending the message authenticator attribute to the server when configuring the RADIUS client.

Configure the User, that is, the realm/domain to which the user belongs. This option is not available if eduroam support is enabled. You can enable SSID mapping and add the SSIDs that will use the configured authentication policy, if there is no realm in the RADIUS request. Ensure that the Called-Station-ID attribute contains the SSID as part of the authentication request.

Enter any Attribute Mappings required for the server and then map them to the usage profile you require and also set the account group. Click Add Mapping to configure the rules for the policy.