Created on
07-27-2023
10:31 PM
Edited on
01-08-2026
11:53 PM
By
Jean-Philippe_P
This article describes that Wifi clients cannot be authenticated to an SSID using WPA enterprise authentication when using an LDAP server or remote LDAP server user group.
FortiGate as a wireless controller for all versions and platforms.
WPA Enterprise configuration with LDAP groups is not supported by definition.
According to the WPA2 or WPA3 Enterprise standard, it is only possible to use a RADIUS authentication server to build the EAP tunnel.
EAPoW – Extensible Authentication Protocol over Wireless.
EAPoL Protocol – Extensible Authentication Protocol over LAN.
The only way to make WPA Enterprise work with LDAP is to have a third-party Radius-LDAP proxy component between the FortiGate and the LDAP server, such as FortiAuthenticator. NPS also has this function.
Use this configuration to create the Radius server on the Windows server and use the same user database.
Technical Tip: Configuring FortiGate and Microsoft NPS (Radius with AD authentication).
It is necessary to create the Windows Server Firewall rules for the Radius because the ones that are automatically created when installing the Service/Role.
Be aware that some NPS releases do not correctly patch the traffic and deny connections. It is a Windows bug, apparently.
Windows Server 2019 - Default NPS Firewall rules (Port 1812 UDP) Not working
After that, proceed to configure the SSID referring to the created RADIUS server.
Deploying WPA2-Enterprise SSID to FortiAP units
Another reason that LDAP does not work directly with WPA enterprise is that it is necessary to configure some authentication method between the supplicant (Wi-Fi client) and the authentication server (RADIUS) so that the authenticator (FortiGate-FortiAP) can generate the EAPOL tunnel. LDAP does not have this function, which is defined in the 802.1X standard.
Be aware of the LAN Edge 7.6 Architect Self-Paced course that explains in detail this problem (pages 38 and 39). The complete course can be accessed by registering at the NSE institute and enrolling in the course.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.