Hi, We are using Aruba as wireless controller and FortiNAC is acting as Local Radius Server, EAP type is TLS and TTLS.
We wanted to enable certificate base authentication for the users who will try to connect wifi.
For Wired users its working perfectly fine but for Wireless Users we seen that the without certificate users are able to connect.. In Radius Logs we seen that the Authentication method is MSCHAPV2, that should not work as its disabled in Radius Default Config.
Please guide.
How many entries are in the RADIUS Local servers?
In the 'Supported EAP Types', only EAP TLS and TTLS are enabled? PEAP/MSCHAPv2 will relay on the Winbind tool to check credentials, if it's not used in this setup you can also limit this authentications by disabling this service.
Dear Emirjon
Only EAP TLS and TTLS is enabled also the the Winbind is disabled.
Than this is technically not possible, make sure the hosts are not currently authenticating with TTLS, that is practically the same as PEAP but the password are in clear text (not using the challenges). At least for testing you can also create a new local server with only TLS selected and use it in model configuration of the WLC.
Keep in mind that even if the RADIUS server doesn't support a type of authentication, it doesn't prevent the hosts from attempting it. As long as the requests are EAP-based, the WLC will forward them to FNAC.
Sorry Emirjon, unable to understand what you are trying to convey.
Authentications that use PEAP/MSCHAPv2 can not be successful if there is no Winbind instance running in FNAC so this statement can not technically happen " for Wireless Users we seen that the without certificate users are able to connect.. In Radius Logs we seen that the Authentication method is MSCHAPV2"
Maybe you are misinterpreting the logs from the successful TTLS authentications or you are just seeing the hosts requests that are using PEAP but this authentication should fail in the end if there is no Winbind instance to check their challenges.
To avoid the confusion, I was suggesting to add another local server for TLS only as shown below:
and use it at the WLC model configuration:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1771 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.