Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lindembertoo
New Contributor

Fortiauthenticator domain computer

Hi guys

 

we are having a trouble to authenticate our domain computer in fortiauthenticator, we already import our ad certificate to fortiauthenticator we can see the request but always failure this is the log that appear 

 

2024-03-12T14:38:03.083294-03:00 FortiAuthenticator radiusd[24103]: (943) Received Access-Request Id 232 from 10.24.0.62:23163 to 172.25.76.127:1812 length 350
2024-03-12T14:38:03.083307-03:00 FortiAuthenticator radiusd[24103]: (943) User-Name = "host/SINTEC010.seed.se.gov"
2024-03-12T14:38:03.083313-03:00 FortiAuthenticator radiusd[24103]: (943) NAS-IP-Address = 0.0.0.0
2024-03-12T14:38:03.083317-03:00 FortiAuthenticator radiusd[24103]: (943) NAS-Identifier = "10.24.5.157/5246-SEDUC-SEDE-BL0"
2024-03-12T14:38:03.083321-03:00 FortiAuthenticator radiusd[24103]: (943) Called-Station-Id = "E0-23-FF-7D-BC-F0:SEDUC-SEDE-BL0"
2024-03-12T14:38:03.083328-03:00 FortiAuthenticator radiusd[24103]: (943) NAS-Port-Type = Wireless-802.11
2024-03-12T14:38:03.083333-03:00 FortiAuthenticator radiusd[24103]: (943) Service-Type = Framed-User
2024-03-12T14:38:03.083337-03:00 FortiAuthenticator radiusd[24103]: (943) NAS-Port = 1
2024-03-12T14:38:03.083341-03:00 FortiAuthenticator radiusd[24103]: (943) Fortinet-SSID = "SEDUC-SEDE-BL0"
2024-03-12T14:38:03.083345-03:00 FortiAuthenticator radiusd[24103]: (943) Fortinet-AP-Name = "AP_SINTEC-224342"
2024-03-12T14:38:03.083349-03:00 FortiAuthenticator radiusd[24103]: (943) Calling-Station-Id = "E0-0A-F6-61-60-23"
2024-03-12T14:38:03.083375-03:00 FortiAuthenticator radiusd[24103]: (943) Connect-Info = "CONNECT 5/0Mbps(Tx/Rx) 11AC"
2024-03-12T14:38:03.083390-03:00 FortiAuthenticator radiusd[24103]: (943) Acct-Session-Id = "65C6C6E4000B58AB"
2024-03-12T14:38:03.083395-03:00 FortiAuthenticator radiusd[24103]: (943) Acct-Multi-Session-Id = "6D893B6FC11265B0"
2024-03-12T14:38:03.083402-03:00 FortiAuthenticator radiusd[24103]: (943) WLAN-Pairwise-Cipher = 1027076
2024-03-12T14:38:03.083407-03:00 FortiAuthenticator radiusd[24103]: (943) WLAN-Group-Cipher = 1027076
2024-03-12T14:38:03.083419-03:00 FortiAuthenticator radiusd[24103]: (943) WLAN-AKM-Suite = 1027077
2024-03-12T14:38:03.083424-03:00 FortiAuthenticator radiusd[24103]: (943) WLAN-Group-Mgmt-Cipher = 1027078
2024-03-12T14:38:03.083428-03:00 FortiAuthenticator radiusd[24103]: (943) Framed-MTU = 1400
2024-03-12T14:38:03.083433-03:00 FortiAuthenticator radiusd[24103]: (943) EAP-Message = 0x02be001f01686f73742f53494e5445433031302e736565642e73652e676f76
2024-03-12T14:38:03.083438-03:00 FortiAuthenticator radiusd[24103]: (943) Message-Authenticator = 0x25fd3dbdab6673742df5eaa4a5fe9e33
2024-03-12T14:38:03.083447-03:00 FortiAuthenticator radiusd[24103]: (943) # Executing section authorize from file /usr/etc/raddb/sites-enabled/default
2024-03-12T14:38:03.083497-03:00 FortiAuthenticator radiusd[24103]: (943) facauth: ===>NAS IP:10.24.0.62
2024-03-12T14:38:03.083509-03:00 FortiAuthenticator radiusd[24103]: (943) facauth: ===>Username:host/SINTEC010.seed.se.gov
2024-03-12T14:38:03.083518-03:00 FortiAuthenticator radiusd[24103]: Not doing PAP as Auth-Type is already set.
2024-03-12T14:38:03.083525-03:00 FortiAuthenticator radiusd[24103]: (943) # Executing group from file /usr/etc/raddb/sites-enabled/default
2024-03-12T14:38:03.083555-03:00 FortiAuthenticator radiusd[24103]: (943) eap: Found authclient from preloaded authclients list for 10.24.0.62: FGT-601E-SEDUC (10.24.0.62)
2024-03-12T14:38:03.084726-03:00 FortiAuthenticator radiusd[24103]: (943) eap: Found vendor 0, attr 61 --> "19"
2024-03-12T14:38:03.084736-03:00 FortiAuthenticator radiusd[24103]: (943) eap: Found authpolicy 'SEDUC_AUTH_DOMAIN' for client '10.24.0.62'
2024-03-12T14:38:03.084827-03:00 FortiAuthenticator radiusd[24103]: (943) eap: EAP session adding &reply:State = 0x7752027a77ed0f58
2024-03-12T14:38:03.084845-03:00 FortiAuthenticator radiusd[24103]: (943) # Executing group from file /usr/etc/raddb/sites-enabled/default
2024-03-12T14:38:03.084853-03:00 FortiAuthenticator radiusd[24103]: (943) Sent Access-Challenge Id 232 from 172.25.76.127:1812 to 10.24.0.62:23163 length 0
2024-03-12T14:38:03.084859-03:00 FortiAuthenticator radiusd[24103]: (943) EAP-Message = 0x01bf00060d20
2024-03-12T14:38:03.084863-03:00 FortiAuthenticator radiusd[24103]: (943) Message-Authenticator = 0x00000000000000000000000000000000
2024-03-12T14:38:03.084867-03:00 FortiAuthenticator radiusd[24103]: (943) State = 0x7752027a77ed0f587a055609b9aeab2b

 

 

3 REPLIES 3
Sx11
Staff
Staff

Hi lindembertoo,

 

from the posted logs it looks like FortiAuthenticator sends an access challenge but there is no Access-Request returned from NAS.

 

can you please check if all configurations steps are as per cookbook below:

 

https://docs.fortinet.com/document/fortiauthenticator/6.5.0/cookbook/3965/computer-authentication-us...

 

Regards

 

sx11
lindembertoo

i noticed now that after make this request and obtain this anwer there is another request and this request is:

Received Access-Request Id 33 from 10.24.0.62:3637 to 172.25.76.127:1812 length 343
2024-03-13T14:46:01.648740-03:00 FortiAuthenticator radiusd[29079]: (17626) User-Name = "host/SINTEC010.seed.se.gov"
2024-03-13T14:46:01.648747-03:00 FortiAuthenticator radiusd[29079]: (17626) NAS-IP-Address = 0.0.0.0
2024-03-13T14:46:01.648753-03:00 FortiAuthenticator radiusd[29079]: (17626) NAS-Identifier = "10.24.5.157/5246-SEDUC-SEDE-BL0"
2024-03-13T14:46:01.648759-03:00 FortiAuthenticator radiusd[29079]: (17626) Called-Station-Id = "E0-23-FF-7D-BC-F0:SEDUC-SEDE-BL0"
2024-03-13T14:46:01.648766-03:00 FortiAuthenticator radiusd[29079]: (17626) NAS-Port-Type = Wireless-802.11
2024-03-13T14:46:01.648773-03:00 FortiAuthenticator radiusd[29079]: (17626) Service-Type = Framed-User
2024-03-13T14:46:01.648780-03:00 FortiAuthenticator radiusd[29079]: (17626) NAS-Port = 1
2024-03-13T14:46:01.648786-03:00 FortiAuthenticator radiusd[29079]: (17626) Fortinet-SSID = "SEDUC-SEDE-BL0"
2024-03-13T14:46:01.648792-03:00 FortiAuthenticator radiusd[29079]: (17626) Fortinet-AP-Name = "AP_SINTEC-224342"
2024-03-13T14:46:01.648801-03:00 FortiAuthenticator radiusd[29079]: (17626) Calling-Station-Id = "E0-0A-F6-61-60-23"
2024-03-13T14:46:01.648807-03:00 FortiAuthenticator radiusd[29079]: (17626) Connect-Info = "CONNECT 0/0Mbps(Tx/Rx) 11AC"
2024-03-13T14:46:01.648813-03:00 FortiAuthenticator radiusd[29079]: (17626) Acct-Session-Id = "65C6C6E4000B77CD"
2024-03-13T14:46:01.648825-03:00 FortiAuthenticator radiusd[29079]: (17626) Acct-Multi-Session-Id = "3FCCB9456AE8BFBD"
2024-03-13T14:46:01.648832-03:00 FortiAuthenticator radiusd[29079]: (17626) WLAN-Pairwise-Cipher = 1027076
2024-03-13T14:46:01.648838-03:00 FortiAuthenticator radiusd[29079]: (17626) WLAN-Group-Cipher = 1027076
2024-03-13T14:46:01.648845-03:00 FortiAuthenticator radiusd[29079]: (17626) WLAN-AKM-Suite = 1027077
2024-03-13T14:46:01.648852-03:00 FortiAuthenticator radiusd[29079]: (17626) WLAN-Group-Mgmt-Cipher = 1027078
2024-03-13T14:46:01.648858-03:00 FortiAuthenticator radiusd[29079]: (17626) Framed-MTU = 1400
2024-03-13T14:46:01.648865-03:00 FortiAuthenticator radiusd[29079]: (17626) EAP-Message = 0x027400060319
2024-03-13T14:46:01.648871-03:00 FortiAuthenticator radiusd[29079]: (17626) State = 0x4f06fbac4f72f67690d0f59ff861081f
2024-03-13T14:46:01.648877-03:00 FortiAuthenticator radiusd[29079]: (17626) Message-Authenticator = 0xa895ffe5ac7b44b993de4e69218ab75e
2024-03-13T14:46:01.648889-03:00 FortiAuthenticator radiusd[29079]: (17626) # Executing section authorize from file /usr/etc/raddb/sites-enabled/default
2024-03-13T14:46:01.648973-03:00 FortiAuthenticator radiusd[29079]: (17626) facauth: ===>NAS IP:10.24.0.62
2024-03-13T14:46:01.648988-03:00 FortiAuthenticator radiusd[29079]: (17626) facauth: ===>Username:host/SINTEC010.seed.se.gov
2024-03-13T14:46:01.649000-03:00 FortiAuthenticator radiusd[29079]: (17626) facauth: ===>Timestamp:1710351961.648562, age:0ms
2024-03-13T14:46:01.649030-03:00 FortiAuthenticator radiusd[29079]: Not doing PAP as Auth-Type is already set.
2024-03-13T14:46:01.649046-03:00 FortiAuthenticator radiusd[29079]: (17626) # Executing group from file /usr/etc/raddb/sites-enabled/default
2024-03-13T14:46:01.649058-03:00 FortiAuthenticator radiusd[29079]: (17626) eap: Expiring EAP session with state 0x4f06fbac4f72f676
2024-03-13T14:46:01.649066-03:00 FortiAuthenticator radiusd[29079]: (17626) eap: Finished EAP session with state 0x4f06fbac4f72f676
2024-03-13T14:46:01.649074-03:00 FortiAuthenticator radiusd[29079]: (17626) eap: Previous EAP request found for state 0x4f06fbac4f72f676, released from the list
2024-03-13T14:46:01.649101-03:00 FortiAuthenticator radiusd[29079]: (17626) eap: Found authclient from preloaded authclients list for 10.24.0.62: FGT-601E-SEDUC (10.24.0.62)
2024-03-13T14:46:01.650925-03:00 FortiAuthenticator radiusd[29079]: (17626) eap: WARNING: No authpolicy for authclient 1 with authtype password
2024-03-13T14:46:01.650943-03:00 FortiAuthenticator radiusd[29079]: (17626) eap: ERROR: No mutually acceptable types found
2024-03-13T14:46:01.651001-03:00 FortiAuthenticator radiusd[29079]: (17626) # Executing group from file /usr/etc/raddb/sites-enabled/default
2024-03-13T14:46:01.651068-03:00 FortiAuthenticator radiusd[29079]: (17626) facauth: Updated auth log 'host/SINTEC010.seed.se.gov': 802.1x authentication failed

Sx11

 

following errors look to point to a Radius policy issue:

 

2024-03-13T14:46:01.650925-03:00 FortiAuthenticator radiusd[29079]: (17626) eap: WARNING: No authpolicy for authclient 1 with authtype password
2024-03-13T14:46:01.650943-03:00 FortiAuthenticator radiusd[29079]: (17626) eap: ERROR: No mutually acceptable types found

 

Make sure you have the Client(NAS) Specified in the Radius Policy and that EAP_TLS is enabled:

https://docs.fortinet.com/document/fortiauthenticator/6.6.0/administration-guide/416152/policies

 

Following KB might help as reference:

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-FortiAuthenticator-802-1x-EAP-TLS...

 

 

sx11
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors