If you use XAuth authentication, you can assign users the virtual IP address stored in the Framed‑IP‑Address field of their record on the RADIUS server. (See RFC 2865 and RFC 2866 for more information about RADIUS fields.) To do this:
• Create a new firewall user group and add the RADIUS server to it.
• In your Phase 1 settings, configure the FortiGate unit as an XAuth server and select from User Group the new user group that you created. For more information, see “Using the FortiGate unit as an XAuth server”.