Client laptop has a cert issued by Microsoft AD (via Intune) the Trusted CA has been imported to the FAC 6.6.0 as per this video:
EAP-TLS Authentication with FortiAuthenticator | Identity and Access Management
The fortigate is set to use the FAC / WPA2 Enterprise as per the instructions, everything is configured as per the fortinet website, but nothing gets sent to the FAC (other traffic using SSL VPN is fine, so its not a connection issue)
Running debugs and logs on both the FAC and the Gate, the EAP-TLS request is not even reaching the FAC,
Fortigate logs show:
2024-11-06 15:09:28 05768.944 70:32:17:11:01:7a <eh> IEEE 802.1X (EAPOL 14B) ==> 70:32:17:11:01:7a ws (0-10.16.152.100:5246) rId 0 wId 1 38:c0:ea:a0:d0:81 2024-11-06 15:09:28 05768.974 70:32:17:11:01:7a <eh> IEEE 802.1X (EAPOL 5B) <== 70:32:17:11:01:7a ws (0-10.16.152.100:5246) rId 0 wId 1 38:c0:ea:a0:d0:81 2024-11-06 15:09:28 05768.974 70:32:17:11:01:7a <eh> recv IEEE 802.1X ver=1 type=1 (EAPOL_START) data len=0
Which show a pattern link below
auth-req
auth-resp
reassoc-req
reassoc-resp
client-disconnected
This then repeats, client machine shows the same sort of log, I have configured and had it checked by TAC, and still cannot get this simple connection working, any help from here is appreciated,
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Are you testing wireless or conneting wired to a Switchport?
The logs you have shared have this message as last one before disconnection:
<eh> recv IEEE 802.1X ver=1 type=1 (EAPOL_START) data len=0
At this point the Authenticator (AP/switch) should send an Identity request packet to get the Host. That is why you see nothing in FortiAuthenticator. That part comes after the identity request/response phase is completed.
So the issue is to be investigated between the Supplicant(endpoint) and the Authenticator.
It might be an issue with 802.1x settings on the Authenticator.
So, this wireless, Client > AP > Fortigate > FAC
The Fortigate is set to use FAC as the Radius Server with WPA2 enterprise. So the issue is likely the AP? that just broadcasts the SSID , could you elaborate please?
Yes the problem is at this communication channel between Client <> AP
Check the 802.1x setting in the AP and check its debugging if it shows any more details on why there is no EAP identity Request packet sent back.
The flow is the following:
Supplicant ---- EAPOL START ----> AP
Supplicant <---- EAP Identity Request ---- AP
Supplicant ---- EAP Identity Response ----> AP
AP --------- Radius Acess-Request ------> FAC
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.