Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nkuhl30
New Contributor II

FortiNAC-F and EAP-TLS

We currently utilize the Local RADIUS server on FortiNAC-F to perform EAP-PEAP. It works well. However, I'd like to transition to EAP-TLS but can't really wrap my head around what needs to be done to make that happen.

 

We have a 3rd-party cert from Sectigo uploaded to FortiNAC-F for Local RADIUS Server (RadSec) and Local RADIUS Server (EAP) [radius]. What else is needed?

5 REPLIES 5
Atul_S
Staff & Editor
Staff & Editor

Hi,

 

Have you tried configuring TLS under the supported EAP type already? Also, make sure the client cert attribute is configured correctly.

 

Thanks,

Atul Srivastava
ebilcari
Staff
Staff

A PKI infrastructure must be in place to issue and manage certificates, which are then distributed to each endpoint. Typically, Microsoft Certificate Authority (CA) is used for this purpose. Some details are also shown in this configuration guide: https://docs.fortinet.com/document/fortinac-f/7.6.0/machine-authentication/730802/tls-certificate

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
AEK

As far as I remember the public certificate will not work with RADIUS. A private cert is required, right?

AEK
AEK
ebilcari

The RADIUS/EAP server certificate is usually signed by a private CA, but it can also be signed by a public one. However, client certificates (EAP-TLS) are rarely signed by public CAs because they are mainly used inside an organization and it's easier to manage them with your own internal CA.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
AEK

Hi Emirjon

I see the doc you shared is new and I guess it was expected by many NAC admins.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors