Chapter 4 Authentication : Examples and Troubleshooting : RADIUS SSO example : Configuring FortiGate regular and RADIUS SSO security policies : Configuring RADIUS SSO security policy
  
Configuring RADIUS SSO security policy
The RADIUS SSO policy allows access for members of specific RADIUS groups.
To configure RADIUS SSO security policy
1. Go to Policy & Objects > Policy > IP4.
2. Select Create New.
3. Enter the following information.
Incoming Interface
Internal
Source Address
internal_network
Source User(s)
Select the user groups you created for RSSO.
Outgoing Interface
wan1
Destination Address
all
Schedule
business_hours
Service
ALL
Action
ACCEPT
NAT
ON
Security Profiles
ON: AntiVirus, WebFilter, IPS, and Email Filter. In each case, select the default profile.
4. Select OK.
To ensure an RSSO-related policy is matched first, the policy should be placed higher in the security policy list than more general policies for the same interfaces.
5. Select OK.