RADIUS Authentication Across VPN Tunnel
We recently moved a clients local server infrastructure to a collocate. Currently they are connected to the infrastructure over a site-to-site VPN (soon to be a point-to-point connection).
As a result, their RADIUS server (NPS) is now across the VPN tunnel. Their main site (outside the Collocate) has a number of FortiAPs that were configured to use WPA/Enterprise with the RADIUS server. This stopped working after we converted them and I've been trying to fix this and we've temporarily implemented a different wireless network for them to work. I can't seem to get the RADIUS working across the tunnel.
It seems to me - if I can control what IP the local Fortigate sends out to the Collocate, and the NPS servers, I should be able to resolve this by configuring the NPS server with a client corresponding to the IP. I don't see anything in the NPS logs referencing this traffic, so it's like it's not even reaching the server. The tunnel between sites allows any/all traffic across.
I found an old posting referencing a similar issue, but the directions seem to be only partially there.
Any thoughts on how to make this work?
Thanks!
