Security

 View Only
last person joined: 6 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

NAS-Port-Type value for FortiGate RADIUS Administration

This thread has been viewed 23 times
  • 1.  NAS-Port-Type value for FortiGate RADIUS Administration

    Posted Sep 21, 2023 09:21 PM

    Hi Airheads,

    I have a customer who wants to use RADIUS with their FortiGate Firewalls for user administration through ClearPass. I need to tighten the ClearPass service match conditions. This will help us distinguish between VPN and Wireless sessions if needed later on. However, I'm unsure about the NAS-Port-Type values that Forti devices send in their RADIUS admin packets.

    I think they use NAS-Port 6 (Administrative User), but I'm not certain. In ClearPass, this would be expressed as: RADIUS:IETF Service-Type EQUALS Administrative-User(6).

    Forti's documentation mentions only 802.11 and VPN attributes; it doesn't cover RADIUS Admin.

    Has anyone done FortiGate RADIUS Admin and knows what values it sends?

    Has anyone worked with FortiGate RADIUS Admin and knows the values it sends?

    I can't access the firewall right now, so I can't review the session logs on ClearPass. If I could, that would provide the answer.



    ------------------------------
    Regards,

    Brett V
    ------------------------------


  • 2.  RE: NAS-Port-Type value for FortiGate RADIUS Administration

    Posted Sep 22, 2023 08:28 AM

    Why not use TACACS Device Admin?  FortiGate supports TACACS




  • 3.  RE: NAS-Port-Type value for FortiGate RADIUS Administration

    Posted Sep 22, 2023 05:43 PM

    The choice to use RADIUS instead of TACACS was a design decision beyond my control.

    Otherwise I only use RADIUS to manage devices where TACACS isn't available.



    ------------------------------
    Regards,

    Brett V
    ------------------------------



  • 4.  RE: NAS-Port-Type value for FortiGate RADIUS Administration

    Posted Sep 22, 2023 06:37 PM
    Got it, I’ve set it up before but I can’t remember the NAS type FortiGate sends. I know it was different than actual wired and wireless clients though. Can you pcap the RADIUS flow?




  • 5.  RE: NAS-Port-Type value for FortiGate RADIUS Administration

    Posted Sep 24, 2023 07:45 PM

    I think a pcap is the only way. I am downloading a trial VM to test as I write this. I will report back. Thanks!



    ------------------------------
    Regards,

    Brett V
    ------------------------------



  • 6.  RE: NAS-Port-Type value for FortiGate RADIUS Administration

    Posted Oct 12, 2023 04:07 AM

    Hi,
    Fortigate is sending Radius:IETF:NAS-Port-Type = 5 for administrative access.

    Regards,

    Mathieu