Skip to main content
rmetzger
Staff
Staff
November 2, 2009

Note about enabling Endpoint NAC in a FortiGate Firewall Policy with authentication redirected to HTTPS

  • November 2, 2009
  • 0 replies
  • 2229 views

Description
When selecting "Enable Endpoint NAC" on a FortiGate Firewall Policy, the following error message may appear "Cannot enable FortiClient checking because authentication is redirected to HTTPS".
Solution

The root cause is that the following option has been enabled (from the WEB based interface): 
User --> Options --> "Redirect HTTP Challenge to a Secure Channel(HTTPS)"
Disabling this option will allow Endpoint NAC checking.

The underlying reason is that the FortiClient cannot attach data to an HTTPS stream to the FortiGate for endpoint NAC checking.




Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!