Skip to main content
scitlak
Staff
Staff
March 8, 2024

Technical Tip: Leveraging Domain Group Membership of Client with EAP-TLS Computer-Based Authentication

  • March 8, 2024
  • 0 replies
  • 1833 views
Description This article describes configuring FortiNAC to leverage Computer Group membership to assign a role to a host with EAP-TLS computer-based authentication.
Scope FortiNAC-F v7.x.x, FortiNAC v9.x.x.
Solution
  1. Configure the LDAP identity to be 'dnsHostname'. 

    1.png
  2. By using LDAP identity, FortiNAC will try to compare dnsHostname against EAP-TLS-Client Certificate Common Name. If they do not match, FortiNAC can not find the host in LDAP and retrieve the appropriate group membership.

2.png
3.png

 

  1. Create an AD Security Group and set the host as a Group member. Then create a new Role and add the group in the role.


    5.png
    4.png

     

  2. After a successful EAP-TLS computer-based authentication, the host will have the appropriate host role.

    6.png