Thanks for sharing this.
Note that SHOULD in an RFC is a strong recommendation, but it also states that there may be valid reasons to ignore/deviate:
SHOULD This word, or the adjective "RECOMMENDED", mean that there
may exist valid reasons in particular circumstances to ignore a
particular item, but the full implications must be understood and
carefully weighed before choosing a different course.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Dec 06, 2023 07:39 AM
From: BrettV
Subject: NAS-Port-Type value for FortiGate RADIUS Administration
If anyone cares - the RADIUS RFC states that either the NAS-Port or NAS-Port-Type attributes, or both, should be present. I was surprised that the NAS-Port attribute was missing from the Fortinet packet captures.
5.41. NAS-Port-Type
Description
This Attribute indicates the type of the physical port of the NAS
which is authenticating the user. It can be used instead of or in
addition to the NAS-Port (5) attribute. It is only used in
Access-Request packets. Either NAS-Port (5) or NAS-Port-Type or
both SHOULD be present in an Access-Request packet, if the NAS
differentiates among its ports.
Type
61 for NAS-Port-Type.
Length
6
Value
The Value field is four octets. "Virtual" refers to a connection
to the NAS via some transport protocol, instead of through a
physical port. For example, if a user telnetted into a NAS to
authenticate himself as an Outbound-User, the Access-Request might
include NAS-Port-Type = Virtual as a hint to the RADIUS server
that the user was not on a physical port.
------------------------------
Regards,
Brett V
------------------------------
Original Message:
Sent: Dec 06, 2023 07:30 AM
From: BrettV
Subject: NAS-Port-Type value for FortiGate RADIUS Administration
Thanks Mathieu,
The firewall was finally configured for RADIUS, and it indeed sends NAS-PORT-TYPE = 5 in the access-request message.
------------------------------
Regards,
Brett V
Original Message:
Sent: Oct 12, 2023 04:07 AM
From: mdavid
Subject: NAS-Port-Type value for FortiGate RADIUS Administration
Hi,
Fortigate is sending Radius:IETF:NAS-Port-Type = 5 for administrative access.
Regards,
Mathieu