<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fortigate authorization with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545361#M538579</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please follow &lt;A _jive_internal="true" href="https://community.cisco.com/message/218958#218958"&gt;Comment 1.&lt;/A&gt; and then &lt;A _jive_internal="true" href="https://community.cisco.com/message/274453#274453"&gt;Comment 6.&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jul 2018 19:43:24 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-07-18T19:43:24Z</dc:date>
    <item>
      <title>Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545350#M538561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone has done Fortigate firewall radius authorization with ISE ?&lt;/P&gt;&lt;P&gt;What are the Radius attributes ? I tried with &lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: sans-serif; font-size: 12px;"&gt;Fortinet-Group-Name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: sans-serif;"&gt;Fortinet-Access-Profile ; but not successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: sans-serif;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: sans-serif;"&gt;Nimmi &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2016 13:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545350#M538561</guid>
      <dc:creator>nimmi.phasil</dc:creator>
      <dc:date>2016-06-16T13:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545351#M538562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nimmi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to consult the Fortinet Firewall documentation for the required attributes for a successful authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have not done any explicit testing with Fortinet products but because ISE supports any standard RADIUS communications with Vendor Specific Attributes (VSAs) it should work. I searched for "fortinet radius authorization attributes" and found the Fortinet Knowledge Base article &lt;A href="http://kb.fortinet.com/kb/viewContent.do?externalId=13837"&gt;&lt;STRONG&gt;Fortinet RADIUS vendor-specific attributes (VSAs) &lt;/STRONG&gt;&lt;/A&gt;which lists the following VSAs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: courier new,courier;"&gt;#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;# Fortinet VSAs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;VENDOR Fortinet 12356&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;BEGIN-VENDOR Fortinet&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;ATTRIBUTE Fortinet-Group-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 string&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;ATTRIBUTE Fortinet-Client-IP-Address 2 ipaddr&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;ATTRIBUTE Fortinet-Vdom-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 string&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;ATTRIBUTE Fortinet-Access-Profile&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 string&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;# Integer Translations&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;END-VENDOR Fortinet&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also attached the above text as a plain text file named &lt;STRONG style="font-family: courier new,courier;"&gt;Fortinet_VSAs.txt&lt;/STRONG&gt; for you to import into ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To import these attributes into ISE:&lt;/P&gt;&lt;P&gt;1) Navigate to &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Dictionaries&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;2) In the &lt;STRONG&gt;Dictionaries&lt;/STRONG&gt; left panel, choose &lt;STRONG&gt;System &amp;gt; RADIUS &amp;gt; RADIUS Vendors&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/96750_pastedImage_10.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;3) You should see a list of RADIUS Vendors that &lt;EM&gt;does not&lt;/EM&gt; include &lt;STRONG&gt;Fortinet&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;4) Select &lt;STRONG&gt;Import&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;5) &lt;STRONG&gt;Browse...&lt;/STRONG&gt; for the &lt;SPAN style="font-family: courier new,courier;"&gt;Fortinet_VSAs.txt&lt;/SPAN&gt; file then click the &lt;STRONG&gt;Import&lt;/STRONG&gt; button and acknowledge the dialog to import the file.&lt;/P&gt;&lt;P&gt;6) You should now see Fortinet in the RADIUS Vendors list:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/96752_pastedImage_18.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;and all of the Fortinet attributes listed under the &lt;STRONG&gt;Dictionary Attributes&lt;/STRONG&gt; tab:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/96753_pastedImage_19.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;So you can use these attributes in your ISE Authorization Profiles per the Fortinet requirements / recommendations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2016 16:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545351#M538562</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-06-20T16:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545352#M538563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN class="font-color-meta j-line2"&gt;Thomas,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="font-color-meta j-line2"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="font-color-meta j-line2"&gt;I know this is an old post but I wonder if you can provide me with the rest of the configuration on ISE so I can Authenticate admin login to Fortigate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="font-color-meta j-line2"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="font-color-meta j-line2"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="font-color-meta j-line2"&gt;Gamal Mohamed&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 18:33:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545352#M538563</guid>
      <dc:creator>MISInfrastructure ITWorx</dc:creator>
      <dc:date>2017-11-14T18:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545353#M538564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fortigate is not our product so you are best to consult Fortigate support, as Thomas suggested.&lt;/P&gt;&lt;P&gt;&lt;A href="http://cookbook.fortinet.com/ssl-vpn-radius-authentication/"&gt;SSL VPN with RADIUS authentication from the Fortinet Cookbook&lt;/A&gt; might help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 18:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545353#M538564</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-14T18:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545354#M538565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hslai,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But can you help me configure the ISE part like authentication and authorization rules and any necessary configuration?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 18:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545354#M538565</guid>
      <dc:creator>MISInfrastructure ITWorx</dc:creator>
      <dc:date>2017-11-14T18:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545355#M538566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried configuring authentication and authorization without success?  If so, maybe you can share your configuration and logs so the community can try to help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 19:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545355#M538566</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-11-14T19:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545356#M538567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We do not test this 3rd party device so can't tell how it working exactly.&lt;/P&gt;&lt;P&gt;&lt;A href="http://kb.fortinet.com/kb/viewContent.do?externalId=FD36127"&gt;Remote Admin login with Radius selecting admin access account profile&lt;/A&gt; looks like it allows using RADIUS to perform device admin so ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Import or define the RADIUS vendor dictionary for Fortigate, as Thomas showed&lt;/LI&gt;&lt;LI&gt;Define an allowed-protocol set or use the existing one to match what configured in Fortigate&lt;/LI&gt;&lt;LI&gt;Define an authorization profile that returns the required vendor attributes. An example shown in the screenshot&lt;IMG alt="Screen Shot 2017-11-14 at 12.01.38 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/113223_Screen Shot 2017-11-14 at 12.01.38 PM.png" style="height: 609px; width: 620px;" /&gt;&lt;/LI&gt;&lt;LI&gt;Define a Network Device group for Fortigate&lt;/LI&gt;&lt;LI&gt;Define a Network Device for Fortigate and specify (4) as its group&lt;/LI&gt;&lt;LI&gt;Define some internal users or add external ID sources and/or define an ID source sequence&lt;/LI&gt;&lt;LI&gt;Create a policy set to condition on (4)&lt;/LI&gt;&lt;LI&gt;In the default authentication policy rule, use (6) as the ID source. Or, you may create additional rules as needed.&lt;/LI&gt;&lt;LI&gt;In the default authorization policy rule, use (3) as the result. Or, you may create additional rules as needed.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 20:12:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545356#M538567</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-14T20:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545357#M538568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hslai,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really appreciate your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gamal Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Nov 2017 11:40:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545357#M538568</guid>
      <dc:creator>MISInfrastructure ITWorx</dc:creator>
      <dc:date>2017-11-16T11:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545358#M538571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am glad that you are able to get it working. If you have some time, please contribute it as a how-to doc in our community and provide details, such as the product versions you tested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Nov 2017 18:20:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545358#M538571</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-16T18:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545359#M538574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hola Gamal Mohamed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tienes algun documento de el proceso que realizaste para integrar fortinet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Podrias compartilo?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gracias.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Saludos.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 21:03:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545359#M538574</guid>
      <dc:creator>hugocarrillo</dc:creator>
      <dc:date>2018-06-13T21:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545360#M538577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hslai&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you help with the attributes for the authorization profile, these attributes where they were obtained? because i configure the similar situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="attributes.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/119421_attributes.PNG" style="height: auto;" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 19:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545360#M538577</guid>
      <dc:creator>hugocarrillo</dc:creator>
      <dc:date>2018-07-18T19:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate authorization with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545361#M538579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please follow &lt;A _jive_internal="true" href="https://community.cisco.com/message/218958#218958"&gt;Comment 1.&lt;/A&gt; and then &lt;A _jive_internal="true" href="https://community.cisco.com/message/274453#274453"&gt;Comment 6.&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 19:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/m-p/3545361#M538579</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-18T19:43:24Z</dc:date>
    </item>
  </channel>
</rss>

