Skip to main content
Sadhi_Jayz
Explorer
December 8, 2024
Solved

Integration of FortiGate, Huawei NAC, and FortiAuthenticator for BYOD Authentication

  • December 8, 2024
  • 9 replies
  • 4141 views

Hello Fortinet Community,

 

I have a network environment consisting of a FortiGate , Windows Active Directory 2019, Huawei iMaster NAC, and a newly purchased FortiAuthenticator . Both the FortiGate firewall and Huawei NAC are configured to authenticate users from Windows Active Directory using LDAP.

Here’s the current workflow:

 

  1. When a user device connects to a switchport, the iMaster NAC detects the user and identifies their organizational unit (OU) (e.g., HR, Technical, etc.).
  2. Based on the detected OU, the switch assigns an IP address to the user from the corresponding VLAN (e.g., VLAN 10 for HR, VLAN 20 for Technical).
  3. After successful NAC authentication, the FortiGate firewall presents a captive portal when the user attempts to access the internet or DMZ. Upon successful authentication via the firewall portal, the appropriate policies are applied based on the user.

The issue arises because users are required to enter their credentials twice: once for NAC authentication and again for the FortiGate firewall captive portal. This dual authentication is inconvenient and negatively impacts the user experience.

 

Unfortunately, I cannot utilize Fortinet Single Sign-On (FSSO) as a solution because many users are on BYOD devices that are not joined to the Active Directory domain.

 

I am looking for a solution to integrate these systems more efficiently with only one captive portal for both NAC and FortiGate firewall.

CP.png

 

Any recommendations or guidance on how to achieve this would be greatly appreciated! Thank you in advance.

 

Best answer by AEK

Hi Sadhi

Basically you keep authenticating with your NAC via RADIUS, and FGT listens for RADIUS accounting records, and so FGT will record the user info (user, group, IP), and you can use them in your firewall rules.

You can start here.

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/85730/radius-single-sign-on-rsso-agent

 

But I guess this is not the unique existing solution for your requirement.

For example there should be a solution where you pull (or forward) login events from your (RADIUS) NAC to your FAC, and then use them on your FortiGate. Or you can configure your NAC to authenticate users from your FAC, and then use them on your FortiGate.

Hope it helps.

9 replies

sjoshi
Staff
Staff
December 8, 2024

Since now you have brought FortiAuth in the picture.. is it also playing the role for user auth?

Also in the FGT lan to internet policy have you called user group in that policy?

Thanks, Salon
Sadhi_Jayz
Explorer
December 8, 2024

Dear @sjoshi ,

 

FortiAuthenticator is a fresh device with just interface and static route configurations.

sjoshi
Staff
Staff
December 8, 2024

So basically your NAC device is also performing the authentication then again the FortiGate correct?

Thanks, Salon
AEK
SuperUser
SuperUser
December 8, 2024

Hi Sadhi

If you are using RADIUS for WiFi authentication then RSSO can be a solution.

AEK
Sadhi_Jayz
Explorer
December 8, 2024

Hello @AEK ,

 

Could you please elaborate further ?

 

AEK
SuperUser
AEKAnswer
SuperUser
December 8, 2024

Hi Sadhi

Basically you keep authenticating with your NAC via RADIUS, and FGT listens for RADIUS accounting records, and so FGT will record the user info (user, group, IP), and you can use them in your firewall rules.

You can start here.

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/85730/radius-single-sign-on-rsso-agent

 

But I guess this is not the unique existing solution for your requirement.

For example there should be a solution where you pull (or forward) login events from your (RADIUS) NAC to your FAC, and then use them on your FortiGate. Or you can configure your NAC to authenticate users from your FAC, and then use them on your FortiGate.

Hope it helps.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!