Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

achraf_harkati
New Contributor II

Fortiauthenticator BYOD

Hi All,


I'm wondering if Anyone has used FortiAuthenticator to perform BYOD ?

I'm testing FAC 5.1.2 in a lab envirement to authenticate WiFi users using EAP-TLS, the FAC has a CA certificate configured.

And I'm stuck at getting devices self-enrolled to obtain a certificate that they can use for EAP-TLS.

I've enabled Device Self-enrollment using a Certificate Template (SCEP request is configured using Wildcard).

At the moment, I'm unable to enroll a client device on the url : https://FAC_IP/cert/scep . I'm getting the following error on the Browser : "operation" parameter is required


I've also tried http (enabled http on the Interface) instead of https and keep getting the same error.


Has anyone faced the same problem before ?
Has anyone succefully got device self-enrollment working on FAC using SCEP ?
Do FAC have an onboarding portal similar to other products such as Aruba Clearpass ?


Your help will be very much appreciated.


Achraf.





1 REPLY 1
RobeWhit1
New Contributor

@Achraf

I have seen this as well. I have been able to authenticate BYOD in the following manner however:

  • Direct the user to HTTPS://FAC_URL
  • Register if there is no login yet, login if there is
  • Go to USER-> Device Enrollment
  • Click Create New
  • Provide information (user should get a certificate in email or download
  • Install certificate to BYOD device
  • Ensure that user is in a group that is allowed to authenticate

Hope this helps!