FortiAuthenticator
FortiAuthenticator provides access management and single sign on.
pksubramanian
Article Id 196684
Description
This article describes how to assign different radius profile for incoming radius request from same Firewall but through different Interface/SSID.

Solution
1) When user connects to interface/SSID called “ 802.1x” the called station ID looks like:

'08-5B-0E-XX-XX-XX:802.1x'



2) Add the following match Radius profile at your FortiAuthenticator Radius service (Radius client)





3) Connecting on different SSID to capture the called station-ID:



4) Create another radius profile for Second interface/SSID and configure the matching radius client attribute: CA-5B-0E-XX-XX-XX:fortinet9.




For a successfully radius authentication log at FAC:


Contributors