Integration of FortiGate, Huawei NAC, and FortiAuthenticator for BYOD Authentication
Hello Fortinet Community,
I have a network environment consisting of a FortiGate , Windows Active Directory 2019, Huawei iMaster NAC, and a newly purchased FortiAuthenticator . Both the FortiGate firewall and Huawei NAC are configured to authenticate users from Windows Active Directory using LDAP.
Here’s the current workflow:
- When a user device connects to a switchport, the iMaster NAC detects the user and identifies their organizational unit (OU) (e.g., HR, Technical, etc.).
- Based on the detected OU, the switch assigns an IP address to the user from the corresponding VLAN (e.g., VLAN 10 for HR, VLAN 20 for Technical).
- After successful NAC authentication, the FortiGate firewall presents a captive portal when the user attempts to access the internet or DMZ. Upon successful authentication via the firewall portal, the appropriate policies are applied based on the user.
The issue arises because users are required to enter their credentials twice: once for NAC authentication and again for the FortiGate firewall captive portal. This dual authentication is inconvenient and negatively impacts the user experience.
Unfortunately, I cannot utilize Fortinet Single Sign-On (FSSO) as a solution because many users are on BYOD devices that are not joined to the Active Directory domain.
I am looking for a solution to integrate these systems more efficiently with only one captive portal for both NAC and FortiGate firewall.

Any recommendations or guidance on how to achieve this would be greatly appreciated! Thank you in advance.
