Skip to main content
nkuhl30
New Member
October 9, 2025
Question

FortiNAC-F and EAP-TLS

  • October 9, 2025
  • 5 replies
  • 893 views

We currently utilize the Local RADIUS server on FortiNAC-F to perform EAP-PEAP. It works well. However, I'd like to transition to EAP-TLS but can't really wrap my head around what needs to be done to make that happen.

 

We have a 3rd-party cert from Sectigo uploaded to FortiNAC-F for Local RADIUS Server (RadSec) and Local RADIUS Server (EAP) [radius]. What else is needed?

5 replies

Atul_S
Staff & Editor
Staff & Editor
October 9, 2025

Hi,

 

Have you tried configuring TLS under the supported EAP type already? Also, make sure the client cert attribute is configured correctly.

 

Thanks,

ebilcari
Staff
Staff
October 13, 2025

A PKI infrastructure must be in place to issue and manage certificates, which are then distributed to each endpoint. Typically, Microsoft Certificate Authority (CA) is used for this purpose. Some details are also shown in this configuration guide: https://docs.fortinet.com/document/fortinac-f/7.6.0/machine-authentication/730802/tls-certificate

Emirjon
AEK
SuperUser
SuperUser
October 13, 2025

As far as I remember the public certificate will not work with RADIUS. A private cert is required, right?

AEK
ebilcari
Staff
Staff
October 13, 2025

The RADIUS/EAP server certificate is usually signed by a private CA, but it can also be signed by a public one. However, client certificates (EAP-TLS) are rarely signed by public CAs because they are mainly used inside an organization and it's easier to manage them with your own internal CA.

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.