Authenticate FortiAP via FortiGate to RADIUS with computer certificates
Hi Community,
I'm stuck with a Problem that I cannot solve - maybe someone can help me out.
SCENARIO:
Using Wireless LAN within a corporate Environment and authenticate users with certificates
GOAL:
Using FortiAPs controlled by a FortiGate to authenticate Computers with their Computer certificate against an existing Windows NPS (Radius) implementation.
First of all - I do have a working LANCOM deployment within our Environment which works exactly like it is supposed to be.
So we have a working Windows Enterprise CA and a working NPS deployment.
I can authenticate with the FortiGate Unit against our RADIUS Server (FortiGate says it is working) - so I've activated the WiFi Controller Feature and linked two FortiAP321C Units. I've created a SSID with a local Bridge to the fortiAPs Interface. Selected WPA2 Enterprise and the Radius Server I've configured.
I cannot get the Windows Clients to authenticate (using the same NPS Profile like the LANCOM APs) with the FortiAP and I don't know what the Problem might be. Using the "old" LANCOM structure (with similar Settings) it is working like a charm (but I have to mention, that in a LANCOM deployment every AP is querying the RADIUS Server). So Computers get their certificates automatically from our Enterprise CA and the RADIUS Server validates them and grants Access.
I haven't found a cookbook mentioning this Scenario so has anybody built this and can help me out?
Any Feedback is appreciated!
Thanks and best regards...
