AnsweredHot!RSSO in 6.2.3 doesn't define "user group" in policy

Author
Art
New Member
  • Total Posts : 3
  • Scores: 2
  • Reward points: 0
  • Joined: 2021/02/09 04:58:05
  • Status: offline
2021/02/09 06:09:04 (permalink)
0

RSSO in 6.2.3 doesn't define "user group" in policy

Hello everyone,
We have FG300 with FortiOS 6.2.3 and Freeradius. Use RSSO to authorize WIFI users. The user falls into the group on FG, but it is not defined in the policy and, accordingly, the policy does not work. We need help, which may be the reason.
 
FortiGate # dia test app radiusd 3
RADIUS server database [vd root]:
"index","time left","ip","endpoint","block status","log status","profile group","ref count","use default profile"
1,07:58:42,"192.168.51.10""host/ARM0796.lokb.spb.ru","allow","no log","<default profile>",1,Yes
2,07:59:57,"192.168.57.4""ushakov","allow","no log","usersLOKB",1,No
 
FortiGate # sh user radius RSSO\ Agent
config user radius
edit "RSSO Agent"
set rsso enable
set rsso-radius-response enable
set rsso-validate-request-secret enable
set rsso-secret "secret"
set rsso-endpoint-attribute User-Name
set rsso-flush-ip-session enable
set rsso-ep-one-ip-only enable
next
end
 
FortiGate # sh user group RADIUS\ users
config user group
edit "RADIUS users"
set group-type rsso
set sso-attribute-value "usersLOKB"
next
end
 
 
Received radius accounting eventvd 0:root Add/Update auth logon for IP 192.168.57.4 for user ushakov
DB 0 insert [ep='ushakov' pg='usersLOKB' ip='192.168.57.4/32'] success
 
User is visible in Monitor > Firewall User Monitor as the rsso user, but policy doesn't work
 
 
 
#1
mschoenberger
New Member
  • Total Posts : 5
  • Scores: 4
  • Reward points: 0
  • Joined: 2021/02/09 12:13:09
  • Status: offline
Re: RSSO in 6.2.3 doesn't define "user group" in policy 2021/02/09 12:30:49 (permalink)
0
I am having the same issue. Users get assigned to the appropriate groups, but when I add the RSSO Group to a policy, it does not work.
 
#2
mschoenberger
New Member
  • Total Posts : 5
  • Scores: 4
  • Reward points: 0
  • Joined: 2021/02/09 12:13:09
  • Status: offline
Re: RSSO in 6.2.3 doesn't define "user group" in policy 2021/02/10 12:57:31 (permalink)
0
WE are going to upgrade the software to 6.2.4 tonight to see if this solves our issue.
#3
Art
New Member
  • Total Posts : 3
  • Scores: 2
  • Reward points: 0
  • Joined: 2021/02/09 04:58:05
  • Status: offline
Re: RSSO in 6.2.3 doesn't define "user group" in policy 2021/02/10 22:28:22 (permalink)
0
We are not yet able to update the version OS, please report the result....)
#4
mschoenberger
New Member
  • Total Posts : 5
  • Scores: 4
  • Reward points: 0
  • Joined: 2021/02/09 12:13:09
  • Status: offline
Re: RSSO in 6.2.3 doesn't define "user group" in policy 2021/02/11 07:33:08 (permalink) ☼ Best Answerby Art 2021/02/11 23:06:38
5 (2)
I have figured it out.
 
You have to set rsso enable in the CLI for the policy before it would work as follows:


CaveCreekUnified-SNA~T01 $ config firewall policy
CaveCreekUnified-SNA~T01 (policy) $ edit <policyID>
CaveCreekUnified-SNA~T01 (52) $ set rsso enable
CaveCreekUnified-SNA~T01 (52) $ end
 
 
#5
Art
New Member
  • Total Posts : 3
  • Scores: 2
  • Reward points: 0
  • Joined: 2021/02/09 04:58:05
  • Status: offline
Re: RSSO in 6.2.3 doesn't define "user group" in policy 2021/02/11 23:06:24 (permalink)
5 (1)
It really solved the problem! Thank you very much, you are cool!))))
#6
mschoenberger
New Member
  • Total Posts : 5
  • Scores: 4
  • Reward points: 0
  • Joined: 2021/02/09 12:13:09
  • Status: offline
Re: RSSO in 6.2.3 doesn't define "user group" in policy 2021/02/12 07:13:51 (permalink)
0
Glad to be of help. I am new to this Firewall, coming from a Cisco ASA and a Netspective Webfilter. I love the full integration and flexibility of the product. I do hope the configuration interfaces mature a bit more so CLI changes are not necessary.
 
#7
Jump to:
© 2021 APG vNext Commercial Version 5.5