This section describes how to integrate FortiGate Remote Access SSL VPN with RSA Authentication Manager using RADIUS.
Configure RSA Authentication Manager
Perform these steps to configure RSA Authentication Manager.
Procedure
- Log in to the RSA Authentication Manager.
- Go to Security Console > RADIUS > RADIUS Clients, and click Add New.
- In the Model section, select Fortinet.
Note: The Model section can remain set to Standard RADIUS if Fortinet RADIUS attributes are not required. However, if these attributes are needed, set the model to Fortinet to enable their use in the RADIUS profile later.
- Click Save & Create Associated RSA Agent > Save > Yes, Save Agent.
Configuration is complete.
Configure FortiGate Access SSL VPN using RADIUS
Perform these steps to configure RSA Authentication Manager Service using RADIUS.
Procedure
- Go to Admin UI of FortiGate > Users & Authentication > RADIUS Servers > New.
- Enter the IP of the RSA Authentication Manager or if you are using Cloud Authentication put the RSA Identity Router Management IP and shared secret.
Note: You can enter up to three servers if you have replicas or 3 identity routers, the second server can be configured via GUI, the tertiary one must be configured from CLI only. configure a tertiary server in the following format.
-
- FEIRDUFG02 # config user radius
- FEIRDUFG02 (radius) # edit RSA-AM
- FEIRDUFG02 (RSA-AM) # set tertiary-server 10.65.65.50
- FEIRDUFG02 (RSA-AM) # set tertiary-secret support1!
- FEIRDUFG02 (RSA-AM) # end
- Go to VPN > SSL VPN Settings.
- In the Authentication/Portal Mapping, select the User Groups configured for RSA Authentication Manager or RSA Cloud Authentication Service.
- Map the required portal (Full Access/Web Access/Tunnel Access) to the RSA User group to authenticate the user against RSA Server using RADIUS.
- In the Policy for the SSL VPN Access. Go to Policy & Objects, and select the IPV4 Policy for the SSL VPN.
- Configure the Source User to be the RSA User Group.
Notes:
- Refer to this section to configure the RADIUS Timeout.
- Refer to this section for the RADIUS return attributes.
Configuration is complete.
Return to the main page.
Related Articles
FortiGate Firewall - RADIUS Configuration Using SSL VPN - RSA Ready Implementation Guide 74Number of Views FortiGate Firewall - SAML Relying Party Configuration Using SSL VPN - RSA Ready Implementation Guide 45Number of Views FortiGate Firewall - SAML My Page SSO Configuration Using SSL VPN - RSA Ready Implementation Guide 18Number of Views FortiGate Firewall - RADIUS Configuration Using Admin Access UI - RSA Ready Implementation Guide 64Number of Views Sophos Firewall - RADIUS Configuration - Authentication Manager - RSA Ready Implementation Guide 5Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Supported On-Demand Authentication (ODA) SMS providers for use with RSA Authentication Manager 8.x Deploying RSA Authenticator 6.2.2 for Windows Using DISM