Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
KayaAtab
New Contributor II

FORTINAC 802.1x fortigate wifi clients usernames

Hello,

 

Customer has FortiGate + fortiap deployments at all of their locations (around 22 and growing). We used to use windows NPS for 802.1x, recently we switched to Fortinac (Fortinac-f 7.2.8). Everything works as expected. But the problem is in the FortiGate GUI, wifi-controller -> wifi clients section we used to view user information as 

Domain/username (COPMPANY/USER1)

 

After the transition, 

half of the users started appear as Domain/computername FQDN (COMPANY/PCHOSTNAME.COMPANY.LOCAL)

 

Both type clients work fine, but this makes IT support a bit tricky since they are mostly using usernames to check on users. Is there a reason for this to happen? If it was for all users, than I would say ok there is ma parameter to deal with. But having some users with usernames and some users with hostnames is a bit confusing.

 

Regards,

 

3 REPLIES 3
ebilcari
Staff
Staff

Based on the description it seems that some hosts are doing User and some Computer authentication. This is mode is chosen from the supplicant configuration in the end host, example below is from Windows 10:

 

authentication mode.PNG

 

This settings/configurations are usually unified and pushed through GPO to the end hosts.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
KayaAtab
New Contributor II

Hello,

 

The clients are wireless,  I guess the solution you provided is for wired connections with wired auto-config. I don't have this option on the wireless interface.

 

 

ebilcari

I used a wired connection as example because it's was easy to show from the lab but the same logic and configurations apply to wireless. You can see the configuration options if you set up a new connection through Control Panel or via GPO.

 

You can use the CMD to check the configurations for existing WiFi networks:

> netsh wlan show profiles TLS-PC

Profile TLS-PC on interface Wi-Fi:
========================================================

Applied: All User Profile

Profile information
-------------------
Version : 1
Type : Wireless LAN
Name : TLS-PC
Control options :
Connection mode : Connect manually
Network broadcast : Connect only if this network is broadcasting
AutoSwitch : Do not switch to other networks
MAC Randomization : Disabled

Connectivity settings
---------------------
Number of SSIDs : 1
SSID name : "TLS-PC"
Network type : Infrastructure
Radio type : [ Any Radio Type ]
Vendor extension : Not present

Security settings
-----------------
Authentication : WPA2-Enterprise
Cipher : CCMP
Authentication : WPA2-Enterprise
Cipher : GCMP
FIPS mode : Disabled
Security key : Absent
802.1X : Enabled
EAP type : Microsoft: Smart Card or other certificate
802.1X auth credential : Machine credential
Cache user information : Yes

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors