Created on 06-26-2024 10:07 PM Edited on 08-22-2024 09:06 AM By Stephen_G
Description
This article describes how FortiAuthenticator authenticates computers using the computer authentication option in a wired or wireless environment using 802.1X EAP-PEAP without a client certificate.
Scope
FortiAuthenticator, 802.1X, EAP-PEAP.
Solution
In this scenario, FortiAuthenticator will authenticate Computers in a Wired/Wireless environment using 802.1X EAP-PEAP (server certificate only, no client certificate involved). If client certificate authentication is required, follow EAP-TLS configuration (see related article). Supplicant configuration is also necessary as we are dealing with Computer authentication instead of User authentication.
This is not covered in this article, but a quick example of a Windows supplicant is visible below.
Note:
The EAP Server Certificate CA must be trusted by the supplicant as well to avoid any certificate trust-related error.
In doubt, consult the debug logs at https://fac-ip/debug/radius (enable the debug mode temporarily for testing).
The Trusted CA used for issuing the server certificate must be imported in FortiAuthenticator.
Starting the implementation:
Note:
The Windows Domain Join is also necessary.
If the Domain Join fails, follow this related KB article: Troubleshooting Tip: FortiAuthenticator error: Failed to join Windows AD network: Domain Name.
...objectClass=computer and also add Radius Attributes to place them in the respective VLAN 200.
Note:
If needed, refine the policy to match only radius requests coming from the wired network, as per the following example. This is not mandatory and it is possible to leave the without any radius criteria in this step.
Select 'PEAP' and 'EAP-MSCHAPv2':
Specify the Realm and filter the group previously created:
Enable Windows AD computer authentication:
Some additional options are available at the end of the Radius policy. In this case, it is possible to have a specific result when the AD computer authentication is successful, another when the User Authentication is successful (if it is enabled in the supplicant), and another when both are successful.
In this example, the supplicant has only computer authentication enabled, and the Radius attributes are associated with the user group previously created:
Related article:
Technical Tip: FortiAuthenticator 802.1x EAP-TLS with computer authentication
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.