Hi all,
Looking for some help deploying FortiClient with EMS using ClearPass for auth, rather than using AD/Azure directly.
ClearPass is already integrated with AD/InTune and has the required info, can we leverage this info to auth FortiClient VPN users? Anyone got a solution doc that can be shared?
Thanks.
As I know ClearPass can be configured as a RADIUS server. You can configure the FGT to authenticate VPN users via RADIUS as shown in this NPS example.
Thanks, can we also apply posture info that the RADIUS server has onto the VPN client, if it knows about them?
Created on 06-16-2024 04:58 AM Edited on 06-16-2024 05:02 AM
So If I get it right you want to change the RADIUS responses based on posture checks of FCT? You can try to integrate FCT EMS as a MDM if ClearPass supports it.
You can also use CP for authentication only and use the FCT EMS tags directly in FGT to block or limit access for non compliant hosts like shown here or here.
User | Count |
---|---|
2270 | |
1232 | |
772 | |
452 | |
396 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.