cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1844
Views
0
Helpful
4
Replies

Using duo with more than 1 LDAP group

c4ipp3r
Level 1
Level 1

Hi folks,

I’m just deploying a DUO solution for one of my customers, install was fine and now I have a issue that I’m trying to setup.

Using a Fortigate:

customer has setup sslvpn using a tunnel - everything works fine DUO send the push to the client and connection is established

Customer setting up a Web Portail - using duo - the same user on the original DUO group does not get to the portal but to the regular default one.

I was thinking in creating a second group only for the portal but my question is :
How should I configure duoRadius to fetch the info ?

TIA

4 Replies 4

IanP1
Level 1
Level 1

Just got off chat with support on a very similar item to this on the Fortinet, and the solution to the issue is to create a second Radius Authenticator on the Forigate, then create an additional Radius_Auto on the proxy. For this new Radius_Auto, give it a new port number, and point it to the AD group that you want to Authenticate against.

Thanks Ian,

So in a way, using more than one a portal or using more than a group, implies on adding another radius instance on the Proxy .

Nice !! Thanks for the input .

I did find that you need to use the CLI to do the different port (example):

config user radius
edit radius-server-one
set server 192.168.1.1
set secret password
set radius-port 1234
end

Yes … this is for the specific radius server port .
You also have , in case you want to change this on the global settings (this for a single Radius)

config system global

set radius_port 1645

end

Thanks again for the input !!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Quick Links