Tagged: RADIUS
3 posts · browse all tags
-
The Wildcard That Wasn't: CVE-2026-26035 and FortiWeb's RADIUS Admin Login Bypass
A non-default setting meant to make RADIUS group matching more flexible turns into a way to log into FortiWeb's GUI and CLI with a username and password that don't need to be correct. CVE-2026-26035, and why "wildcard" is a word worth treating with suspicion in any auth config.
-
Configuring RADIUS Admin Auth on FortiGate SDWAN: RBAC and Three User Profiles (Part 2 of 2)
Part 2 of 2 on RADIUS for FortiGate SDWAN. Walks through the FortiOS config end-to-end — RADIUS server entry, group-to-profile mapping via VSA, three worked RBAC examples (senior engineer, NOC operator, compliance auditor), and the verification commands you'll need.
-
RADIUS vs TACACS+ on FortiGate SDWAN: Choosing the Right AAA Backend (Part 1 of 2)
Part 1 of 2 on RADIUS for FortiGate SDWAN. Covers the protocol differences vs TACACS+, the RADIUS server options worth knowing (NPS, FortiAuthenticator, FreeRADIUS, ISE, Okta, Duo, Entra), and when each protocol is the right call for FortiOS.