Fortinet black logo

Cookbook

Creating a RADIUS policy

Copy Link
Copy Doc ID 23809264-eafe-11eb-97f7-00505692583a:926059
Download PDF

Creating a RADIUS policy

A RADIUS policy must be configured in order to allow RADIUS authentication for the selected client.

To create a RADIUS policy:
  1. Go to Authentication > RADIUS Service > Policies, and click Create New.
  2. Under RADIUS clients, configure the following, and click Next.
    1. Policy name: Enter a name for this policy, for example: FGT-Computer-TLS.
    2. RADIUS clients: Add the previously configured FortiGate RADIUS client to the Chosen RADIUS Clients section.
  3. Under RADIUS attribute criteria, click Next.

  4. Under Authentication type, choose Client Certificates (EAP-TLS), and click Next.
  5. Under Identity source, configure the following, and click Next.
    1. Username format: Select your preferred username format, for example: realm\username.
    2. Realms: In the Realms table, select your AD realm.
      You can additionally apply a group filter if required.
  6. Under Authentication factors, click Next.
  7. Under RADIUS response, click Save and exit.

Creating a RADIUS policy

A RADIUS policy must be configured in order to allow RADIUS authentication for the selected client.

To create a RADIUS policy:
  1. Go to Authentication > RADIUS Service > Policies, and click Create New.
  2. Under RADIUS clients, configure the following, and click Next.
    1. Policy name: Enter a name for this policy, for example: FGT-Computer-TLS.
    2. RADIUS clients: Add the previously configured FortiGate RADIUS client to the Chosen RADIUS Clients section.
  3. Under RADIUS attribute criteria, click Next.

  4. Under Authentication type, choose Client Certificates (EAP-TLS), and click Next.
  5. Under Identity source, configure the following, and click Next.
    1. Username format: Select your preferred username format, for example: realm\username.
    2. Realms: In the Realms table, select your AD realm.
      You can additionally apply a group filter if required.
  6. Under Authentication factors, click Next.
  7. Under RADIUS response, click Save and exit.