Chapter 3 Authentication for FortiOS 5.0 : SSO using RADIUS accounting records : Configuration Overview
  
Configuration Overview
The general steps to implement RADIUS Single Sign-On are:
1. If necessary, configure your RADIUS server. The user database needs to include user group information and the server needs to send accounting messages.
2. Create the FortiGate RADIUS SSO agent.
3. Define local user groups that map to RADIUS groups.
4. Create an identity-based security policy and create authentication rules as appropriate for the different user groups that are permitted access.