Skip to main content
sensorsinc
New Member
May 23, 2011
Question

WiFi Authentication Problem

  • May 23, 2011
  • 7 replies
  • 5831 views
Hello! When I setup my SSL VPN authentication, I setup LDAP (User->Remote->LDAP) to connect to my Windows 2003 SP2 DC. In User->User I set a username for each person and set them to " match user on LDAP server" . I created a Firewall group that allows SSL-VPN access and added everyone to it. Besides having to use the AD full name (Fred Smith) instead of username (fsmith), everything works great. So when I went to setup the authentication for my WPA2-Enterprise WiFi network, I created a new group just for WiFi users. I added the same users that were in the SSL VPN group. And gave it shot, but I can' t seem to get authenticated. I tried all different kinds of combinations of full name, username, with and without domain, and I can' t get connected. So I created a test user with a password stored on the firewall and added it to the newly created group for WiFi users. That account works. I just can' t get the ldap users to authenticate when making a WiFi connection. Anyone have any tips? Would also be curious to know how to get the SSL VPN authentication to use username instead of full name, but that is very minor. Thanks, Jamie!

    7 replies

    Matthijs
    New Member
    May 24, 2011
    For the SSL-VPN: use sAMAccountName at Common Name Identifier in the LDAP server config in your FortiGate. Never used ldap for FortiWifi, sorry ;) Should not be to hard i gues. What software version do you use?
    sensorsinc
    New Member
    May 24, 2011
    Thanks Matthijs, sAMAccountName did the trick! It fixed the username vs full name. Still no luck with the WiFi. Firewall FW - 4.0, build0441,110318 (MR3) FortiAP FW - FAP21B-v4.0-build214
    rwpatterson
    New Member
    May 24, 2011
    What firmware version are you running?
    romanr
    New Member
    May 24, 2011
    For WPA2-Enterprise authentication you will need to use Radius... All that EAP handling cannot get transported over ldap!! Install IAS(W2k3)/NPS(W2k8) on your domain controllers and use the radius server from windows! best regards, Roman
    sensorsinc
    New Member
    May 24, 2011
    Thanks for the info Roman!
    sensorsinc
    New Member
    May 24, 2011
    I started re-reading the Deploying Wireless Networks document to learn more about RADIUS and there are several lines that seem to indicate that LDAP is supported. Documentation being documentation, I opened a support ticket. Thanks for all the help and I will report back when I hear from tech support.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!