FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
SAJUDIYA
Staff
Staff
Article Id 381336
Description

This article describes an issue with the RADIUS server EAP type that cannot be processed by the server when the user connects to the Wi-Fi SSID. While checking RADIUS server logs, the following logs were observed for the user:

 

Error logs from Windows:

RADIUS Client:
Client Friendly Name: test
Client IP Address: 10.x.x.x 

Authentication Details:
Connection Request Policy Name: Use Windows authentication for all users
Network Policy Name: Wireless
Authentication Provider: Windows
Authentication Server: xxx.domain.com
Authentication Type: EAP
EAP Type: -
Account Session Identifier: 36363643393238373030314536323245
Logging Results: Accounting information was written to the local log file.
Reason Code: 22
Reason: The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.

Scope All versions of FortiOS.
Solution
  1. Make sure that the following settings matched under certificate Authority(local) where RADIUS server is configured:

certificate settings.png

 

  1. Make sure that the certificate is valid. If not, renew it on the NPS server.
  1. If the same issue persists, it is possible a local certificate stored on the server hard drive is corrupted. It is therefore necessary to create a new NPS server, which should resolve the issue.