Note about enabling Endpoint NAC in a FortiGate Firewall Policy with authentication redirected to HTTPS
Description
When selecting "Enable Endpoint NAC" on a FortiGate Firewall Policy, the following error message may appear "Cannot enable FortiClient checking because authentication is redirected to HTTPS".
Solution
The root cause is that the following option has been enabled (from the WEB based interface):
User --> Options --> "Redirect HTTP Challenge to a Secure Channel(HTTPS)"
Disabling this option will allow Endpoint NAC checking.
The underlying reason is that the FortiClient cannot attach data to an HTTPS stream to the FortiGate for endpoint NAC checking.
The underlying reason is that the FortiClient cannot attach data to an HTTPS stream to the FortiGate for endpoint NAC checking.
