Fortinet white logo
Fortinet white logo

CLI Reference

config user external-identity-provider

config user external-identity-provider

Configure external identity provider.

config user external-identity-provider
    Description: Configure external identity provider.
    edit <name>
        set type {option}
        set version [v1.0|beta]
        set url {string}
        set user-attr-name {string}
        set group-attr-name {string}
        set port {integer}
        set source-ip {string}
        set interface-select-method [auto|specify]
        set interface {string}
        set server-identity-check [disable|enable]
        set timeout {integer}
    next
end

config user external-identity-provider

Parameter

Description

Type

Size

Default

name

External identity provider name.

string

Maximum length: 35

type

External identity provider type.

option

-

Option

Description

ms-graph

Microsoft Graph server.

version

External identity API version.

option

-

Option

Description

v1.0

MS Graph REST API v1.0.

beta

MS Graph REST API beta (debug build only).

url

External identity provider URL (e.g. "https://example.com:8080/api/v1").

string

Maximum length: 127

user-attr-name

User attribute name in authentication query.

string

Maximum length: 63

userPrincipalName

group-attr-name

Group attribute name in authentication query.

string

Maximum length: 63

id

port

External identity provider service port number.

integer

Minimum value: 0 Maximum value: 65535

0

source-ip

Use this IPv4/v6 address to connect to the external identity provider.

string

Maximum length: 63

interface-select-method

Specify how to select outgoing interface to reach server.

option

-

auto

Option

Description

auto

Set outgoing interface automatically.

specify

Set outgoing interface manually.

interface

Specify outgoing interface to reach server.

string

Maximum length: 15

server-identity-check

Enable/disable server's identity check against its certificate and subject alternative name(s).

option

-

enable

Option

Description

disable

Do not check server's identity against its certificate and subject alternative name(s).

enable

Check server's identity against its certificate and subject alternative name(s).

timeout

Connection timeout value in seconds.

integer

Minimum value: 1 Maximum value: 60

5

config user external-identity-provider

config user external-identity-provider

Configure external identity provider.

config user external-identity-provider
    Description: Configure external identity provider.
    edit <name>
        set type {option}
        set version [v1.0|beta]
        set url {string}
        set user-attr-name {string}
        set group-attr-name {string}
        set port {integer}
        set source-ip {string}
        set interface-select-method [auto|specify]
        set interface {string}
        set server-identity-check [disable|enable]
        set timeout {integer}
    next
end

config user external-identity-provider

Parameter

Description

Type

Size

Default

name

External identity provider name.

string

Maximum length: 35

type

External identity provider type.

option

-

Option

Description

ms-graph

Microsoft Graph server.

version

External identity API version.

option

-

Option

Description

v1.0

MS Graph REST API v1.0.

beta

MS Graph REST API beta (debug build only).

url

External identity provider URL (e.g. "https://example.com:8080/api/v1").

string

Maximum length: 127

user-attr-name

User attribute name in authentication query.

string

Maximum length: 63

userPrincipalName

group-attr-name

Group attribute name in authentication query.

string

Maximum length: 63

id

port

External identity provider service port number.

integer

Minimum value: 0 Maximum value: 65535

0

source-ip

Use this IPv4/v6 address to connect to the external identity provider.

string

Maximum length: 63

interface-select-method

Specify how to select outgoing interface to reach server.

option

-

auto

Option

Description

auto

Set outgoing interface automatically.

specify

Set outgoing interface manually.

interface

Specify outgoing interface to reach server.

string

Maximum length: 15

server-identity-check

Enable/disable server's identity check against its certificate and subject alternative name(s).

option

-

enable

Option

Description

disable

Do not check server's identity against its certificate and subject alternative name(s).

enable

Check server's identity against its certificate and subject alternative name(s).

timeout

Connection timeout value in seconds.

integer

Minimum value: 1 Maximum value: 60

5