Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GauravPandya
New Contributor III

802.1x authentication for wifi users

Hello Everyone,

I want to implement 802.1x authentication on wifi users. We have FortiAPs managed by fortigate. I want to use device based authentication with certificate. If certificate exist in laptop/MAC then only users can connect to wifi.
I have gone through some admin guides and threads but it is not clear. Can somebody please reply with steps or document how I can achieve this requirement?
Thanks in advance.

4 REPLIES 4
AEK
SuperUser
SuperUser

Hello

If I'm not wrong FG can be in this case a basic RADIUS server (I see it in my SSID config) but it seems it is so basic so it doesn't support certificate authentication. In this case you may need an external RADIUS server, you will then configure it on FG (User & Device > RADIUS Servers) and use it as RADIUS server in your SSID as authentication server.

AEK
AEK
ndumaj
Staff
Staff

Hello @GauravPandya 

Please find the guide from Microsoft for host configuration:
https://learn.microsoft.com/en-us/windows-server/networking/technologies/extensible-authentication-p...

Also this article that might help you:

https://community.fortinet.com/t5/FortiAP/Technical-Note-EAP-TLS-wireless-LAN-deployment-on-Android-...

BR

- Happy to help, hit like and accept the solution -
GauravPandya
New Contributor III

Thanks. It really helps.

We have OKTA server so we will use OKTA as Radius server.

ndumaj
Staff
Staff

Great,
Happy to help you!

- Happy to help, hit like and accept the solution -
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors