Hot!IPv6 users not authenticated by RSSO and FSSO

Author
shane.caznet
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2015/04/08 22:52:19
  • Status: offline
2018/01/15 17:29:27 (permalink)
0

IPv6 users not authenticated by RSSO and FSSO

Hi
 
We have 2 Fortigate 300D running FortiOS 5.4.7 in a HA A-A cluster.
 
Our users are authenticated to our Fortigates by 2 ways: 1) FSSO using the Active Directory collector agent for domain joined machines, and 2) RSSO using Radius Accounting from our wireless (Ubiquiti) to Microsoft NPS Radius for non-domain joined BYOD devices such as iPads.
 
Our users show as authenticated with IPv4 sessions (user to IP address) as expected for both authentication types. However, we do not see any authenticated users with IPv6 addresses. When users access the internet using an IPv6 address, they get our unauthenticated user policy.
 
I'm not sure what I need to change to get both the IPv4 and IPv6 authentication for every user. Does Fortigate support dual-stack for user auth in this scenario? Am I missing something?
 
Shane
post edited by shane.caznet - 2018/01/15 17:35:08
#1

6 Replies Related Threads

    xsilver_FTNT
    Expert Member
    • Total Posts : 368
    • Scores: 61
    • Reward points: 0
    • Joined: 2015/02/02 03:22:58
    • Status: offline
    Re: IPv6 users not authenticated by RSSO and FSSO 2018/01/15 23:46:06 (permalink)
    0
    Hi Shane,
     
    there is no GA release supporting IPv6 in FSSO as of now.
    See "FSSO does not currently support IPv6." in FortiOS Release Notes page 14 'Fortinet Single Sign-On' section in integration support part.
    https://docs.fortinet.com/uploaded/files/4088/fortios-v5.6.3-release-notes.pdf
     
    There is IPv6 support in RADIUS Accounting (RSSO) on FortiOS.
    If you send Framed-IPv6-Address then FortiGate will process it.

    Example:
    ----------
    # sent data via radclient (Freradius-utils)
    root@SRV-DEB-1:~# echo "Acct-Status-Type = Start, User-Name = JohnDoe , Class = ClassProfile , Framed-IPv6-Address = 2001:db8:0:69a1::1" | radclient -4 -c 1 -n 1 -x 192.168.32.251:1813 acct fortinet
    Sending Accounting-Request of id 19 to 192.168.32.251 port 1813
    Acct-Status-Type = Start
    User-Name = "JohnDoe"
    Class = 0x436c61737350726f66696c65
    Framed-IPv6-Address = 2001:db8:0:69a1::1

    # result in debug app radiusd -1
    FGVM_251 # Received radius accounting eventvd 0:root Add/Update auth logon for IP 2001:db8:0:69a1::1 for user (null)
    DB 0 insert [ep='n/a' pg='ClassProfile' ip='2001:db8:0:69a1::1'] success

    # result in DB
    FGVM_251 # diagnose test application radiusd 33
    RADIUS server database [vd root]:
    "index","start time","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile"
    1,1516088594,07:59:37,"2001:db8:0:69a1::1","","n/a","n/a","<default profile>",0,Yes

    Best regards,
    Tomas

    Kind Regards,
    Tomas
    #2
    sviusa
    New Member
    • Total Posts : 11
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/12/29 00:50:10
    • Status: offline
    Re: IPv6 users not authenticated by RSSO and FSSO 2018/08/09 02:36:00 (permalink)
    0
    Hello,
     
    I'm in the same config as yours. trying to make the same exact thing. for now no way.
    I've tried to make the machine IPv6 only and the log on fortigate shows :
     
    RADIUS server database [vd root]:
    "index","start time","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile"
    1,1533749461,00:00:00,"::/32""LABUSER1","allow","no log","A12-RUN+]L",1,No
    2,1533805132,00:00:00,"192.168.10.166""LABUSER2","allow","no log","A12-RUN+]�",1,No
     
    Seams that the AP is not forwarding the framed-IPv6-Address...
     
    is there any other means to achieve this ? maybe using Forticlient ?
     
    thanks,
     
    Regards,
     
     
    #3
    Jeff_FTNT
    Gold Member
    • Total Posts : 227
    • Scores: 17
    • Reward points: 0
    • Joined: 2005/06/14 16:27:00
    • Status: offline
    Re: IPv6 users not authenticated by RSSO and FSSO 2018/08/09 08:48:36 (permalink)
    0
    FOS 6.0 support ipv6 FSSO.
     
    IPv6 support for FSSO
    (1) connecting FSSO agent over IPv6;
    (2) accepting and applying IPv6 FSSO logons for IPv6 firewall policies.
    #4
    sviusa
    New Member
    • Total Posts : 11
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/12/29 00:50:10
    • Status: offline
    Re: IPv6 users not authenticated by RSSO and FSSO 2018/08/10 00:25:00 (permalink)
    0
    Hi All,
     
    We have planned to move to fortios 6.0.2 on our validation environment this week-end.
    @Jeff, is there any special thing to know for FSSO implementation under this os release ? Specific configuration on AD agent ? i don't have seen updated documentation so far.
     
    Keep posted.
     
    Regards,
     
    Stephane
    #5
    Jeff_FTNT
    Gold Member
    • Total Posts : 227
    • Scores: 17
    • Reward points: 0
    • Joined: 2005/06/14 16:27:00
    • Status: offline
    Re: IPv6 users not authenticated by RSSO and FSSO 2018/08/10 09:07:28 (permalink)
    0
    IPv6 FSSO need FSSO Agent support IPv6 too. May be FSSO Agent is not released.
    #6
    sviusa
    New Member
    • Total Posts : 11
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/12/29 00:50:10
    • Status: offline
    Re: IPv6 users not authenticated by RSSO and FSSO 2018/08/13 02:11:08 (permalink)
    0
    Hello,
     
    I have made the test and logon under IPv6 are not monitored by the FSSO agent on AD.
    I will wait for the new agent to continue the POC.
    Also, i don't think that my Fortigate talks to FSSO agent under IPv6 event after setting the sourceIP6 in conf.
     
    Thanks for your support guys,
     
    Regards,
     
    #7
    Jump to:
    © 2018 APG vNext Commercial Version 5.5