- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
802 1x Certificate based authentication where FNAC is acting as radius
Hi, We are using Aruba as wireless controller and FortiNAC is acting as Local Radius Server, EAP type is TLS and TTLS.
We wanted to enable certificate base authentication for the users who will try to connect wifi.
For Wired users its working perfectly fine but for Wireless Users we seen that the without certificate users are able to connect.. In Radius Logs we seen that the Authentication method is MSCHAPV2, that should not work as its disabled in Radius Default Config.
Please guide.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How many entries are in the RADIUS Local servers?
In the 'Supported EAP Types', only EAP TLS and TTLS are enabled? PEAP/MSCHAPv2 will relay on the Winbind tool to check credentials, if it's not used in this setup you can also limit this authentications by disabling this service.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear Emirjon
Only EAP TLS and TTLS is enabled also the the Winbind is disabled.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Than this is technically not possible, make sure the hosts are not currently authenticating with TTLS, that is practically the same as PEAP but the password are in clear text (not using the challenges). At least for testing you can also create a new local server with only TLS selected and use it in model configuration of the WLC.
Keep in mind that even if the RADIUS server doesn't support a type of authentication, it doesn't prevent the hosts from attempting it. As long as the requests are EAP-based, the WLC will forward them to FNAC.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry Emirjon, unable to understand what you are trying to convey.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Authentications that use PEAP/MSCHAPv2 can not be successful if there is no Winbind instance running in FNAC so this statement can not technically happen " for Wireless Users we seen that the without certificate users are able to connect.. In Radius Logs we seen that the Authentication method is MSCHAPV2"
Maybe you are misinterpreting the logs from the successful TTLS authentications or you are just seeing the hosts requests that are using PEAP but this authentication should fail in the end if there is no Winbind instance to check their challenges.
To avoid the confusion, I was suggesting to add another local server for TLS only as shown below:
and use it at the WLC model configuration:
If you have found a solution, please like and accept it to make it easily accessible for others.
