12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

System Administrators<br />

Administrators<br />

You can authenticate an administrator using a password stored on the <strong>FortiGate</strong><br />

unit or a RADIUS server, or use PKI certificate-based authentication. Optionally,<br />

you can store all administrator accounts on a RADIUS server. RADIUS-based<br />

accounts on the same RADIUS server share the same access profile.<br />

Configuring RADIUS authentication for administrators<br />

If you want to use a RADIUS server to authenticate administrators in your VDOM,<br />

you must configure the authentication before you create the administrator<br />

accounts. To do this you need to:<br />

• configure the <strong>FortiGate</strong> unit to access the RADIUS server<br />

• create a user group with the RADIUS server as its only member<br />

The following procedures assume that there is a RADIUS server on your network<br />

populated with the names and passwords of your administrators. For information<br />

on how to set up a RADIUS server, see the documentation for your RADIUS<br />

server.<br />

To configure the <strong>FortiGate</strong> unit to access the RADIUS server<br />

1 Go to User > RADIUS.<br />

2 Select Create New.<br />

3 Enter the following information:<br />

Name<br />

A name for the RADIUS server. You use this name when you create the<br />

user group.<br />

Server Name/IP The domain name or IP address of the RADIUS server.<br />

Server Secret The RADIUS server secret. The RADIUS server administrator can<br />

provide this information.<br />

4 Select OK.<br />

To create the administrator user group<br />

1 Go to User > User Group.<br />

2 Select Create New.<br />

3 In the Group Name field, type a name for the administrator group.<br />

4 In the Available Users list, select the RADIUS server name.<br />

5 Select the green right arrow to move the name to the Members list.<br />

6 Select any protection profile.<br />

7 Select OK.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 163

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!