
User management
Page 66
FortiRecorder 2.4.2 Administration Guide
Configuring RADIUS authentication
Except for local users, FortiRecorder also support RADIUS user authentication. You will use the
RADIUS authentication profiles when you add user accounts.
To configure a RADIUS query
1.
Go to
System > Authentication > RADIUS
.
2.
Click
New
.
A dialog appears.
3.
Configure these settings:
4.
Click
OK
.
To test the query, select this profile when configuring an account (
),
then attempt to authenticate using that account’s credentials.
Setting name
Description
Profile name
Type a name (such as
RADIUS-query
) that can be referenced by
other parts of the configuration. Do not use spaces or special
characters. The maximum length is 35 characters.
Server name/IP
Type the fully qualified domain name (FQDN) or IP address of the
RADIUS server that will be queried when an account referencing this
profile attempts to authenticate.
Server port
Type the port number on which the authentication server listens for
queries.
The IANA standard port number for RADIUS is 1812.
Protocol
Select which authentication method is used by the RADIUS server:
•
Password Authentication
•
Challenge Handshake Authentication
(CHAP)
•
Microsoft Challenge Handshake Authentication
(CHAP)
•
Microsoft Challenge Handshake Authentication V2
(CHAP
version 2)
•
Default Authentication Scheme
NAS IP/Called
station ID
Type the NAS IP address or Called Station ID (for more information
about RADIUS Attribute 31, see
Microsoft Vendor-specific
RADIUS Attributes). If you do not enter an IP address, the IP address
of the FortiRecorder network interface used to communicate with the
RADIUS server will be applied.
Server secret
Type the secret required by the RADIUS server. It must be the same as
the secret that is configured on the RADIUS server.
Server requires
domain
Enable if the authentication server requires that users authenticate
using their full email address (such as
) and not
just the user name (such as
user1
).