Chapter 11 IPsec VPN for FortiOS 5.0 : FortiClient dialup-client configurations : Configuration overview : Using virtual IP addresses : Assigning VIPs by RADIUS user group
  
Assigning VIPs by RADIUS user group
If you use XAuth authentication, you can assign users the virtual IP address stored in the Framed‑IP‑Address field of their record on the RADIUS server. (See RFC 2865 and RFC 2866 for more information about RADIUS fields.) To do this:
Set the DHCP server IP Assignment Mode to User-group defined method. This is an Advanced setting. See “To configure a DHCP server on a FortiGate interface”.
Create a new firewall user group and add the RADIUS server to it.
In your phase 1 settings, configure the FortiGate unit as an XAuth server and select from User Group the new user group that you created. For more information, see “Using the FortiGate unit as an XAuth server”.
Configure the FortiClient application to use XAuth. See “Adding XAuth authentication”.