基于FreeRADIUS与FortiGate防火墙的用户带宽限制问题求助
It looks like you're hitting a common pitfall: FortiGate doesn't natively recognize WISPr or Mikrotik-specific RADIUS attributes for bandwidth control. Instead, you need to use Fortinet's proprietary RADIUS attributes or leverage standard attributes mapped to FortiGate's traffic shaping policies. Here's how to resolve this step by step:
1. Use Fortinet's Native RADIUS Bandwidth Attributes
FortiGate supports two custom attributes for dynamic bandwidth limiting:
Fortinet-FortiGate-Bandwidth-Up: Limits upstream bandwidth (unit: bps)Fortinet-FortiGate-Bandwidth-Down: Limits downstream bandwidth (unit: bps)
Note: You mentioned a 64KB limit—this translates to 512 Kbps (since 1 KB/s = 8 Kbps; 64 * 8 = 512). If your FortiGate uses 1024-based units, use 524288 bps instead, but 512000 bps is the standard industry value for 64KB/s.
Configure FreeRADIUS to Send These Attributes
First, ensure FreeRADIUS has the Fortinet dictionary loaded. Most distributions include dictionary.fortinet by default, but if not, add this to your root dictionary file:
$INCLUDE dictionary.fortinet
Then, update your user profile (in the users file or your RADIUS policy) to include the attributes:
your_user Cleartext-Password := "your_password" Fortinet-FortiGate-Bandwidth-Up = 512000, Fortinet-FortiGate-Bandwidth-Down = 512000
2. Enable Dynamic Bandwidth Control on FortiGate
You need to tell FortiGate to apply the RADIUS-provided bandwidth limits based on your access type:
- For WiFi SSIDs: Go to WiFi & Switch Controller > SSIDs > [Your SSID] > Authentication and enable "Dynamic Bandwidth Control".
- For VPN/PPPoE: Go to VPN > IPsec > [Your Tunnel] or Network > PPPoE > [Your Service], then under authentication settings, enable "Apply RADIUS Bandwidth Limits".
3. Verify RADIUS Traffic and FortiGate Logs
To confirm attributes are being sent and received correctly:
Use
tcpdumpon your FreeRADIUS server to capture Access-Accept packets:tcpdump -i any port 1812 -vvv | grep -i fortinetLook for the
Fortinet-FortiGate-Bandwidth-UpandFortiGate-Bandwidth-Downattributes in the output.On FortiGate, enable RADIUS debugging to check if attributes are parsed properly:
diagnose debug application radius -1 diagnose debug enableAuthenticate a user and check the debug logs for references to bandwidth attributes.
4. Alternative: Use Filter-Id for Traffic Shaping Policies
If native attributes don't work (e.g., older FortiGate firmware), use the standard Filter-Id attribute:
- On FortiGate, create a traffic shaping policy with your 64KB/s limit (name it something like
64k_bw_limit). - In FreeRADIUS, return the policy name via
Filter-Id:your_user Cleartext-Password := "your_password" Filter-Id = "64k_bw_limit" - On FortiGate, configure your access service to apply the policy mapped by
Filter-Id.
Final Checks
- Ensure your FortiGate firmware is up to date (older versions may have limited RADIUS attribute support).
- Confirm the RADIUS server is reachable from FortiGate and that shared secrets match exactly.
内容的提问来源于stack exchange,提问作者Abobaker EngIt

