Skip to main content
Poseidonn
New Member
December 6, 2024
Question

Fortinac LDAP and RADIUS

  • December 6, 2024
  • 2 replies
  • 1075 views

Hi,

 

When is not possible to have an Windows NPS for corporate VLAN authentication, Winbind can be a good solution?

 

Thanks.

 

Regards

2 replies

slovepreet
Staff
Staff
December 6, 2024

Hi, 

You can use Winbind but keep in mind that Winbind is used to provide MSCHAPv2 authentication only. If using a different scheme, such as EAP-TTLS/PAP or EAP-TLS, configuration is not required.

 

More information can be found here https://docs.fortinet.com/document/fortinac-f/7.6.0/administration-guide/670285/winbind

 

I hope this will be helpful. 

Regards

 

ebilcari
Staff
Staff
December 7, 2024

Winbind is a tool used to validate the challenges for authentication types that don't exchange passwords (emulate a windows PC) like MSCHAPv2, some details are shown in this article.
FNAC has Winbind included in its local RADIUS server that can be used to replace Windows NPS server roles and also offer advanced NAC features.

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.