Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nkuhl30
New Contributor II

BYOD and RADIUS

We're a K-12 boarding school with a ton of BYOD devices on our network. Currently, we have three SSIDs: Open (Mac auth), 802.1x MS-CHAP v2, and WPA2-Personal for guest access.

 

We need to keep the open network around for devices that can't do 802.1x auth like gaming consoles. My question is, how do you handle BYOD device authentication? Is 802.1x still the only game in town? We need it to be fast and simple. I'd like to avoid EAP-TLS for these types of devices as it can make the onboarding more difficult. This is why we're still using EAP-PEAP.

 

Any suggestions?

3 REPLIES 3
ebilcari
Staff
Staff

The simplest way is to use MAC filtering/authentication through RADIUS and host registration, authentication through the Portal. There is an example shown in this article for guests.

If the users already have an account in LDAP or in a remote RADIUS server, a Standard login through the portal is also possible. There is a dedicated portal section for Game device registration.
If the network need to be secure than EAP-PEAP is still good to go, FNAC supports a local RADIUS server and Winbind.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
pminarik
Staff
Staff

Nothing has really changed with wifi in the recent years. It's still either open, PSK, or EAP (802.1x/"Enterprise"), nothing else.

(captive portal, or anything else, being optional on top of either of the primary three methods)

[ corrections always welcome ]
nkuhl30
New Contributor II

How does everyone handle EAP-TLS through a portal registration? 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors