Configure the RADIUS server
You need to configure the RADIUS server to work with the RSA ACE/Server. See the RSA ACE/Server Administrator's Guide.
Configure the RSA ACE/Server to support the RADIUS server
See the RSA ACE/Server Installation Guide.
Configure the FortiGate unit as an Agent Host
You need to set up the FortiGate unit as an Agent Host within the RSA ACE/Server database.
- On the RSA ACE/Server computer, go to Start > PRograms > RSA ACE/Server, and then Database Administration - Host Mode.
- On the Agent Host menu, select Add Agent Host.
- In the Name field, enter a name for the FortiGate unit.
- In the Network address field, enter the FortiGate unit ip address.
- Select Secondary Nodes and define all hostname/IP addresses that resolve to the FortiGate unit.
If needed, refer to the RSA ACE/Server documentation for more information.
Add the RADIUS server
The FortiGate unit will use the RADIUS server to authenticate SecurID users.
- Go to User > RADIUS and select Create New.
- In the Name field, enter a name for the RADIUS server.
- In the Server Name/IP and Server Secret fields, enter the appropriate information about the RADIUS server you configured for use with SecureID.
Create a SecurID user group
You need to create a user group with the SecurID RADIUS server as its only member.
- Go to User > User Group.
- Select Create New.
- In the Name field, enter a name for the group.
- In the Available Users/Groups list, select the RADIUS server you configured for use with SecureID.
- Select the right arrow button to move the selected server to the Members list.
- Select OK.
Use the SecurID user group for authentication
You can use the SecureID user group in several FortiGate features that authenticate by user group:
- Firewall policies - select the Authentication checkbox and add the SecurID user group to the Allowed list.
- XAuth in dialup VPN - in the VPN Phase 1 configuration Advanced settings, in the XAuth section, select Enable as Server and choose the SecurID user group.
- PPTP VPN - in the PPTP configuration, choose the SecurID user group.