Skip to main content
cserna_FTNT
Staff
Staff
August 5, 2017

Technical Tip: Authenticating users using MSCHAP2 PEAP

  • August 5, 2017
  • 0 replies
  • 13691 views

Description

 

This article describes the configuration required to permit FortiAuthenticator to join the AD environment.

 

Scope

 

FortiAuthenticator.

Solution

 

Once a remote LDAP server is added, it's possible to set the parameter required to add FortiAuthenticator as a machine inside the Active Director Environment.

Under the configuration for the remote LDAP server, go to Authentication -> Remote Auth. Servers -> LDAP.
Enable the Windows Active Directory Domain Authentication check box.

 

matanaskovic_0-1648124142285.png

 

Fill in the above fields:

  • Kerberos real name: Enter the domain’s name on DNS name in upper cases. Right click on the Domain Object in the AD server to obtain the value required.
  • Domain NetBIOS Name: Enter the domain’s prefix in upper case.
  • FortiAuthenticator NetBIOS name: Name used to identify the FortiAuthenticator on the domain.
  • Administrator Username: Name of the user account used to associate the FortiAuthenticator with the domain name. The user must have at least Domain User Privileges. Use simple format, in some version neither DC nor UPN is supported.
  • Administrator password: Password associated to the user specified.

Once configuration is complete, go to Monitor -> Authentication -> Windows AD and see the connection as 'Joined Domain, connected':

 

matanaskovic_1-1648124263495.png

 

Next, 'Use Windows AD Domain Authentication' on the RADIUS clients configuration to use MSCHAP (V2).

 

If FortiAuthenticator is not correctly joined to the domain, this option will be unavailable.

 

matanaskovic_2-1648124389887.png

 

Related Article:

 

https://community.fortinet.com/t5/FortiAuthenticator/Troubleshooting-Tip-FortiAuthenticator-error-Failed-to-join/ta-p/193327

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!