Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
simonorch
Contributor

FAP14C, home office and WPA2-enterprise

We' re testing the suitability of using the 14C for home offices and roaming users as a remote AP. i' m having problems with getting WPA2-enterprise to work, using PSK it works fine but with enterprise the MS NPS server is getting authentication attempts as EAP rather than PEAP even though the client is correctly configured. Tried changing WTP profile from using DTLS to clear text but no difference. I' ve configured the ssid to tunnel the connection as i guess local bridging wont work Does WPA2-enterprise actually work in this scenario? we' re using the latest production builds on both the central FG and AP
Senior Consultant working with Fortinet products since 2009
Senior Consultant working with Fortinet products since 2009
7 REPLIES 7
Baptiste
Contributor II

Hi, did you try with FG internal user/group just to know if problem come from NPS ?

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
FortiRack_Eric
New Contributor III

I' m using a FAP-11C everywhere with 2 SSID' s WPA2-PSK and WPA2-Enterprise and works like charm. Setting DTLS encryp only works in more or less latest FAP firmware Cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
simonorch
Contributor

Hi, did you try with FG internal user/group just to know if problem come from NPS ?
This is why i tried it with PSK, the same NPS with the same profile, certs etc. is being used for another SSID on branch office 221B+60D set up with WPA enterprise and works like a charm. NPS is getting EAP instead of PEAP from the client for some reason, thanks Eric for confirming that it does work, i take it you' re using DTLS?
Senior Consultant working with Fortinet products since 2009
Senior Consultant working with Fortinet products since 2009
yzhang_FTNT
Staff
Staff

DTLS is used for FAP and controller data tunnel, and is not related to the method used for client authentication. Also for WPA enterprise, the FAP/controller just relays those authentication messages between the radius server and client. and which method to use is not selected by the controller.
simonorch
Contributor

OK, that' s helpful, so there' s no way the AP\FG can change what is being passed from client to radius server which suggests to me it' s client side.
Senior Consultant working with Fortinet products since 2009
Senior Consultant working with Fortinet products since 2009
Bromont_FTNT
Staff
Staff

What authentication method are you using? Local (pointing to a radius usergroup on the Fortigate) or RADIUS server? Radius Server will just pass through to NPS.
simonorch
Contributor

radius server. I need to test client side myself, not that i don' t trust the trust the customer testing it but we' ve all been there
Senior Consultant working with Fortinet products since 2009
Senior Consultant working with Fortinet products since 2009
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors