cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3000
Views
0
Helpful
5
Replies

Send ISE RADIUS accounting message to another system

alibarzoodeh
Level 1
Level 1

Hi

is there possible ISE send RADIUS accounting to another system like Fortigate?

in my scenario, we have fortigate at edge block and ISE for dot1x user authentication.

we want enable Fortigate RADIUS Single Sign On with ISE as RADIUS Server.

5 Replies 5

jj27
Spotlight
Spotlight

Yes you can send accounting messages to an external syslog server, but I'm not sure about what you are trying to do with the Fortigate and if it can accept Syslog messages or not.

If you go to Administration->Logging->Remote Logging targets and setup your Fortigate information then click Logging Categories from the Logging administration page and click on the Accounting->RADIUS accounting link in the list to configure the logs to be sent there.

jan.nielsen
Level 7
Level 7
Unfortunaly i think Fortigate expects radius accounting packets sent as they are originally from the switch or wlc as radius, not as syslog events. You cpuld probably have some sort of radius "proxy" set up to replicate the accounting packets to ise and to your fortigate.

steigja
Level 3
Level 3

Hello,

   I have the same issue with trying to authenticate ISE with the Fortigate for radius SSO.  Have you have any luck with this?  Have you been able to use a radius proxy to transform the syslogs into radius accounting packets?  Thanks

Jason

Hi,

was anybody able to crack this problem?

Thanks,

Wim

gabo
Cisco Employee
Cisco Employee

I see there is an enhancement bug to add this feature in ISE

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvd83297