Skip to main content
RandomTechGuy
New Member
December 1, 2023
Question

FortiGate and Fortiap with Radius authentication

  • December 1, 2023
  • 18 replies
  • 9611 views

Hi guys.

A customer  asked for FortiGate WIFI with Radius authentication.

I tried to do it on a lab first.

I have windows server 2016 with a ad domain and radius server with Certificate issued.

Also I have Fortigate 40F and Fortiap 220B ( I know its old but this is what i currently have)

I have configured WPA2  Enterprise with radius server and created a group that belongs to the radius server and everything looks fine.

When i login to the wifi i put my credentials and its taking its time on checking network environment.

Eventually I'm able to login.. I'm getting apipa address and when I check the Fortigate wifi clients i see that the user is logged in and was assigned an IP.

Can you guys help ? I dont know what am i doing wrong :\

18 replies

dbu
Staff
Staff
December 1, 2023

It looks like there is some issue with the DHCP server configured for this VPN . Doble check the configuration and DHCP scope

On the FortiGate what IP do you see for this user? Same APIPA?
You can also run packet capture to see if the DHCP negotiation process. 

distillednetwork
Explorer II
December 1, 2023

A couple of questions to help narrow it down:

Are you using a bridge or tunnel SSID?

- If bridged did you assign a default vlan?

- If Tunneled do you have the DHCP server enabled on that ssid interface?

Are you trying to send back any vlans in the radius response or just an access-accept?

RandomTechGuy
New Member
December 1, 2023

@dbu 
Hi its on the same scope and in the DHCP  I see  the domain and the user and a legitimate IP for exmaple 10.40.40.2

I tried to see dhcp negotiation by running this commands

 

diag debug reset
diag debug application dhcpc -1
diag debug enable

and it didn't show any results..

@distillednetwork 

I  used tunnel with DHCP server enabled

And i think its just access accept.. if the user is in a group "WIFI" so it can get access to the internet

I

dbu
Staff
Staff
December 2, 2023

You can run a packet capture and filter with port 67/68 :
diag sniffer packet <interface_name/any> "port 67 or port 68" 6 0 1

RandomTechGuy
New Member
December 3, 2023

@dbu  @jiahoong112 

I ran the commands but it doesn't show anything

I see in the DHCP that the mac address got an IP with username and password

 

DHCP.JPG

 

dbu
Staff
Staff
December 3, 2023

Can you try to assign an IP address manually as per the IP pool it should belong to and try again if it works? 

distillednetwork
Explorer II
December 3, 2023

if you look at the scope are there any DHCP options that are set?  

config system dhcp server

 

I would also run a wireshark capture on the client and see if you get the DHCP OFFER to the client.  

vbandha
Staff
Staff
December 3, 2023

@RandomTechGuy 

Release the IP for the end device and then run the packet sniffer for DHCP:
diag sniffer packet any "port 67 or port 68" 4 0 l

 

Also run wireshark on end device at the same time

 

Check if the DORA process completes on both sides. 

When Fortigates sends offer, it will put the IP in DHCP lease even if DORA has not completed. So in that case you would see IP Assigned on fortigate but no IP on end device.  

ebilcari
Staff
Staff
December 5, 2023

In WiFi usually the DHCP is usually wrongfully blamed :) In my experience that is not always the case. 

You can check if the authentication is successful and the VLAN is returned by the RADIUS server:

VLAN ID.PNG

or from CLI

GW # diagnose wireless-controller wlac -c sta
-------------------------------STA 1----------------------------
STA mac : 88:46...
live : 96 (ts=17605)
authed : yes
wtp : 0-10.5.32.54:25246
rId : 1
aId : 1
wId : 1
bssid : 70:4c:a5:...
cap : 0111
VLAN tag : 01ff (511)
ACL deny cnt : 0
802.11kvr :
Os Info : Android13

 

Since you are using an old AP to avoid any compatibility issue between the AP and the client I would suggest to temporarily change the SSID configuration to Personal and if everything works fine including DHCP and access you can revert it to Enterprise.

Emirjon
RandomTechGuy
New Member
December 9, 2023

@ebilcari 

I changed it to WPA 2 Personal and i was able to connect... I'm really lost

 

BTW i created a new lab for this and now in the fortigate itself i dont see that the user received ip

from dhcp 

 

here are my configurations

1.PNG2.PNG3.PNG4.PNG5.PNG6.PNG7.PNG8.PNG9.PNG10.PNG

ebilcari
Staff
Staff
December 11, 2023

Since the DHCP works with WPA2 this is now clearly an authentication or VLAN assignment issue.

What's the authentication status the output when you run this command:

GW # diagnose wireless-controller wlac -c sta

 

You can also get the debugs from FGT while authenticating:

diagnose debug app eap_proxy 31

debug application wpad 8

diagnose debug enable

 

Since you already created a fully functional Enterprise solution why don't you enable dynamic VLAN assignment through RADIUS and include the VLAN in response. You will have it ready if you want to do segmentation in the future.

Emirjon
RandomTechGuy
New Member
December 11, 2023

 

Hi @ebilcari 

i ran the logs.. these are the Results 

ebilcari
Staff
Staff
December 12, 2023

RADIUS server is responding with accept:

00540.799 HOSTAPD: <0>10.x.x.x:5246<1-0> Revived 307 bytes RADIUS message from authentication server <10.0.x.x:1812> by sock 13
RADIUS message: code=2 (Access-Accept) identifier=20 length=307

the 4 way handshake looks completed:

23755.853 44:xxx <eh> ***pairwise key handshake completed*** (RSN)

and the authentication status of the host is correct:

FortiGate-60E # diagnose wireless-controller wlac -c sta
------------------------------STA 1----------------- -----------
STA mac : 44:xxxx
authed: yes
VLAN tag : 0000 (0)

 

I found out on of my notes that the DHCP service may be stuck sometimes for WiFi hosts, running this command have solved it, can you give it a try:

# execute wireless-controller restart-acd

Emirjon
RandomTechGuy
New Member
December 12, 2023

hi @ebilcari 
It's important to know that yesterday before I ran the diagnose on the FortiGate

I turned on the FortiGate + server + FortiAp (The whole equipment is for lab so its not on when I'm not using) so I don't think that running this command will do anything.

Is it possible that the AP is having problems ?

ebilcari
Staff
Staff
December 12, 2023

I can't tell, you can run a sniffer directly in the AP to have a better view of what is happening. I have a relay in this SSID (unicast), you should see broadcast traffic.

sniffer.PNG

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!