Re: [PacketFence-users] FortiGate VPN Auth based on AD Group Membership

2021-05-12 Thread Chris Crawford via PacketFence-users
for iOS<https://aka.ms/o0ukef> From: Fabrice Durand Sent: Tuesday, May 11, 2021 11:03:37 PM To: packetfence-users@lists.sourceforge.net Cc: Chris Crawford Subject: Re: [PacketFence-users] FortiGate VPN Auth based on AD Group Membership ✉External messag

Re: [PacketFence-users] FortiGate VPN Auth based on AD Group Membership

2021-05-11 Thread Fabrice Durand via PacketFence-users
Hello Chris, First we don't compute the role from the source for Fortigate, we just do a mschap verification then if it's authenticated then we allow the access. It misses a little bit of code to do that but it's not something really complicated. Next the condition in the radius filter you

[PacketFence-users] FortiGate VPN Auth based on AD Group Membership

2021-05-11 Thread Chris Crawford via PacketFence-users
Good morning, I'm looking to assign a user a role, based on their membership in AD and have that returned to the FortiGate to allow the user to connect to the VPN. User login comes in from the VPN. The User Authenticates. User-Name = "chris" NAS-IP-Address = 10.10.20.10 Called-Station-Id =