Chapter 3 Authentication for FortiOS 5.0 : SSO using RADIUS accounting records
  
SSO using RADIUS accounting records
A FortiGate unit can authenticate users transparently who have already authenticated on an external RADIUS server. Based on the user group to which the user belongs, the security policy applies the appropriate UTM profiles. RADIUS SSO is relatively simple because the FortiGate unit does not interact with the RADIUS server, it only monitors RADIUS accounting records that the server emits. These records include the user’s IP address and user group.
After the initial set-up, changes to the user database, including changes to user group memberships, are made on the external RADIUS server, not on the FortiGate unit.
This section describes:
User’s view of RADIUS SSO authentication
Configuration Overview
Configuring the RADIUS server
Creating the FortiGate RADIUS SSO agent
Defining local user groups for RADIUS SSO
Creating security policies
Example: webfiltering for student and teacher accounts