I'm trying to test a user authentication by Domain user not success.
Could help me to with it?
https://community.fortinet.com/t5/FortiNAC/Technical-Tip-FortiNAC-Computer-Machine-authentication-by...
I need more information.
Are you trying to configure PEAP with computer authentication? If yes, FNAC need to be joined in the domain like shown here: Technical Tip: MSCHAPv2 authentication, join FortiNAC in domain and checks for the authentications to work. This guide Machine Authentication includes all necessary steps.
You need to check if the authentication succeeds first, than use a simple User/Host profile to match with the Network Access Policy. The RADIUS logs will give more information about the authentication results. The details that are shown in the mentioned article can be later leveraged in case you want to limit host access based on RADIUS attributes.
Is there another way? The customer does not prefer this way.
if CA fails we could facing a lot of issue.
EAP-TLS is a viable option that is also supported by FNAC, but its implementation is a bit more complex, as each host requires its own certificate for authentication. A Public Key Infrastructure (PKI) must be in place to issue and distribute these certificates.
Created on ‎07-30-2025 07:37 AM Edited on ‎07-30-2025 07:37 AM
Why do they not prefer this? Why would they prefer to send AD usernames and passwords with broken encryption? How exactly would a "CA fail"?
Does that work on any NAC version, like 7.4?
If you have a version with the built-in RADIUS server yes.
Are you using PEAP/MS-CHAPv2? You should not be using that in 2025. It uses broken encryption and should no longer be used. Credential guard will block this by default on modern versions of Windows.
Created on ‎07-29-2025 08:28 PM
Yes, so what encryption method should I used instead of PEAP/MSCHAPv2
EAP-TLS or TEAP.
User | Count |
---|---|
2571 | |
1365 | |
796 | |
652 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.