Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
williasthomas192004
New Contributor III

FortiNAC Computer/Machine authentication

I'm trying to test a user authentication by Domain user  not success.
Could help me to with it?

https://community.fortinet.com/t5/FortiNAC/Technical-Tip-FortiNAC-Computer-Machine-authentication-by...

I need more information. 

11 REPLIES 11
ebilcari
Staff
Staff

Are you trying to configure PEAP with computer authentication? If yes, FNAC need to be joined in the domain like shown here: Technical Tip: MSCHAPv2 authentication, join FortiNAC in domain and checks for the authentications to work. This guide Machine Authentication includes all necessary steps.

 

You need to check if the authentication succeeds first, than use a simple User/Host profile to match with the Network Access Policy. The RADIUS logs will give more information about the authentication results. The details that are shown in the mentioned article can be later leveraged in case you want to limit host access based on RADIUS attributes.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
williasthomas192004

Is there another way? The customer does not prefer this way.

if CA fails we could facing  a lot of issue.

ebilcari

EAP-TLS is a viable option that is also supported by FNAC, but its implementation is a bit more complex, as each host requires its own certificate for authentication. A Public Key Infrastructure (PKI) must be in place to issue and distribute these certificates.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
adambomb1219

Why do they not prefer this? Why would they prefer to send AD usernames and passwords with broken encryption? How exactly would a "CA fail"?

williasthomas192004

Does that work on any NAC version, like 7.4?

adambomb1219

If you have a version with the built-in RADIUS server yes.

adambomb1219
SuperUser
SuperUser

Are you using PEAP/MS-CHAPv2? You should not be using that in 2025. It uses broken encryption and should no longer be used. Credential guard will block this by default on modern versions of Windows.

williasthomas192004

Yes, so what encryption method should I used instead of PEAP/MSCHAPv2

adambomb1219

EAP-TLS or TEAP.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors