Fortigate - RADIUS, LDAP, or TACACS+ response wait period

Information

The number of seconds that the FortiGate unit waits for responses from remote RADIUS, LDAP, or TACACS+ authentication servers. The range is 0 to 300 seconds, 0 means no timeout. To improve security keep the remote authentication timeout at the default value of 5 seconds. However, if a RADIUS request needs to traverse multiple hops or several RADIUS requests are made, the default timeout of 5 seconds may not be long enough to receive a response.

Solution

To set the remote auth timeout, use the following command:

config system global
set remoteauthtimeout 5
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12, CSCv6|16.4

Plugin: FortiGate

Control ID: e94871c0e1076a502055a492160d00d54a66a7faef148ca97acd7fac62bda730