You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于FreeRADIUS与FortiGate防火墙的用户带宽限制问题求助

Fixing FortiGate Bandwidth Limitation via FreeRADIUS

It looks like you're hitting a common pitfall: FortiGate doesn't natively recognize WISPr or Mikrotik-specific RADIUS attributes for bandwidth control. Instead, you need to use Fortinet's proprietary RADIUS attributes or leverage standard attributes mapped to FortiGate's traffic shaping policies. Here's how to resolve this step by step:

1. Use Fortinet's Native RADIUS Bandwidth Attributes

FortiGate supports two custom attributes for dynamic bandwidth limiting:

  • Fortinet-FortiGate-Bandwidth-Up: Limits upstream bandwidth (unit: bps)
  • Fortinet-FortiGate-Bandwidth-Down: Limits downstream bandwidth (unit: bps)

Note: You mentioned a 64KB limit—this translates to 512 Kbps (since 1 KB/s = 8 Kbps; 64 * 8 = 512). If your FortiGate uses 1024-based units, use 524288 bps instead, but 512000 bps is the standard industry value for 64KB/s.

Configure FreeRADIUS to Send These Attributes

First, ensure FreeRADIUS has the Fortinet dictionary loaded. Most distributions include dictionary.fortinet by default, but if not, add this to your root dictionary file:

$INCLUDE dictionary.fortinet

Then, update your user profile (in the users file or your RADIUS policy) to include the attributes:

your_user Cleartext-Password := "your_password"
    Fortinet-FortiGate-Bandwidth-Up = 512000,
    Fortinet-FortiGate-Bandwidth-Down = 512000

2. Enable Dynamic Bandwidth Control on FortiGate

You need to tell FortiGate to apply the RADIUS-provided bandwidth limits based on your access type:

  • For WiFi SSIDs: Go to WiFi & Switch Controller > SSIDs > [Your SSID] > Authentication and enable "Dynamic Bandwidth Control".
  • For VPN/PPPoE: Go to VPN > IPsec > [Your Tunnel] or Network > PPPoE > [Your Service], then under authentication settings, enable "Apply RADIUS Bandwidth Limits".

3. Verify RADIUS Traffic and FortiGate Logs

To confirm attributes are being sent and received correctly:

  • Use tcpdump on your FreeRADIUS server to capture Access-Accept packets:

    tcpdump -i any port 1812 -vvv | grep -i fortinet
    

    Look for the Fortinet-FortiGate-Bandwidth-Up and FortiGate-Bandwidth-Down attributes in the output.

  • On FortiGate, enable RADIUS debugging to check if attributes are parsed properly:

    diagnose debug application radius -1
    diagnose debug enable
    

    Authenticate a user and check the debug logs for references to bandwidth attributes.

4. Alternative: Use Filter-Id for Traffic Shaping Policies

If native attributes don't work (e.g., older FortiGate firmware), use the standard Filter-Id attribute:

  1. On FortiGate, create a traffic shaping policy with your 64KB/s limit (name it something like 64k_bw_limit).
  2. In FreeRADIUS, return the policy name via Filter-Id:
    your_user Cleartext-Password := "your_password"
        Filter-Id = "64k_bw_limit"
    
  3. On FortiGate, configure your access service to apply the policy mapped by Filter-Id.

Final Checks

  • Ensure your FortiGate firmware is up to date (older versions may have limited RADIUS attribute support).
  • Confirm the RADIUS server is reachable from FortiGate and that shared secrets match exactly.

内容的提问来源于stack exchange,提问作者Abobaker EngIt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:16:22