Fortinet white logo
Fortinet white logo

CLI Reference

config authentication scheme

config authentication scheme

Configure Authentication Schemes.

config authentication scheme
    Description: Configure Authentication Schemes.
    edit <name>
        set method [ntlm|basic|...]
        set negotiate-ntlm [enable|disable]
        set kerberos-keytab {string}
        set domain-controller {string}
        set saml-idp-portal {var-string}
        set saml-server {string}
        set saml-timeout {integer}
        set require-tfa [enable|disable]
        set fsso-guest [enable|disable]
        config user-database
            Description: Authentication server to contain user information; "local" .
            edit <name>
            next
        end
        set ssh-ca {string}
    next
end

config authentication scheme

Parameter

Description

Type

Size

method

Authentication methods .

option

-

Option

Description

ntlm

NTLM authentication.

basic

Basic HTTP authentication.

digest

Digest HTTP authentication.

form

Form-based HTTP authentication.

negotiate

Negotiate authentication.

saml

SAML-IDP authentication (requires external FortiAuthenticator).

saml-sp

SAML-SP authentication. (Fortiproxy will act as SAML SP).

fsso

Fortinet Single Sign-On (FSSO) authentication.

rsso

RADIUS Single Sign-On (RSSO) authentication.

ssh-publickey

Public key based SSH authentication.

x-auth-user

User from HTTP x-authenticated-user header.

negotiate-ntlm

Enable/disable negotiate authentication for NTLM .

option

-

Option

Description

enable

Enable negotiate authentication for NTLM.

disable

Disable negotiate authentication for NTLM.

kerberos-keytab

Kerberos keytab setting.

string

Maximum length: 35

domain-controller

Domain controller setting.

string

Maximum length: 35

saml-idp-portal

external SAML-IDP authentication Portal URL.

var-string

Maximum length: 255

saml-server

SAML configuration.

string

Maximum length: 35

saml-timeout

SAML Authentication value in seconds . Default is 120s.

integer

Minimum value: 30 Maximum value: 1200

require-tfa

Enable/disable two-factor authentication .

option

-

Option

Description

enable

Enable two-factor authentication.

disable

Disable two-factor authentication.

fsso-guest

Enable/disable user fsso-guest authentication .

option

-

Option

Description

enable

Enable user fsso-guest authentication.

disable

Disable user fsso-guest authentication.

ssh-ca

SSH CA name.

string

Maximum length: 35

config authentication scheme

config authentication scheme

Configure Authentication Schemes.

config authentication scheme
    Description: Configure Authentication Schemes.
    edit <name>
        set method [ntlm|basic|...]
        set negotiate-ntlm [enable|disable]
        set kerberos-keytab {string}
        set domain-controller {string}
        set saml-idp-portal {var-string}
        set saml-server {string}
        set saml-timeout {integer}
        set require-tfa [enable|disable]
        set fsso-guest [enable|disable]
        config user-database
            Description: Authentication server to contain user information; "local" .
            edit <name>
            next
        end
        set ssh-ca {string}
    next
end

config authentication scheme

Parameter

Description

Type

Size

method

Authentication methods .

option

-

Option

Description

ntlm

NTLM authentication.

basic

Basic HTTP authentication.

digest

Digest HTTP authentication.

form

Form-based HTTP authentication.

negotiate

Negotiate authentication.

saml

SAML-IDP authentication (requires external FortiAuthenticator).

saml-sp

SAML-SP authentication. (Fortiproxy will act as SAML SP).

fsso

Fortinet Single Sign-On (FSSO) authentication.

rsso

RADIUS Single Sign-On (RSSO) authentication.

ssh-publickey

Public key based SSH authentication.

x-auth-user

User from HTTP x-authenticated-user header.

negotiate-ntlm

Enable/disable negotiate authentication for NTLM .

option

-

Option

Description

enable

Enable negotiate authentication for NTLM.

disable

Disable negotiate authentication for NTLM.

kerberos-keytab

Kerberos keytab setting.

string

Maximum length: 35

domain-controller

Domain controller setting.

string

Maximum length: 35

saml-idp-portal

external SAML-IDP authentication Portal URL.

var-string

Maximum length: 255

saml-server

SAML configuration.

string

Maximum length: 35

saml-timeout

SAML Authentication value in seconds . Default is 120s.

integer

Minimum value: 30 Maximum value: 1200

require-tfa

Enable/disable two-factor authentication .

option

-

Option

Description

enable

Enable two-factor authentication.

disable

Disable two-factor authentication.

fsso-guest

Enable/disable user fsso-guest authentication .

option

-

Option

Description

enable

Enable user fsso-guest authentication.

disable

Disable user fsso-guest authentication.

ssh-ca

SSH CA name.

string

Maximum length: 35