I am wanting to change the hostname of our fortigates so they are more self explanitory. However we have a NPS server running and the NAS identifier is set to the present hostname of the fortigate.
Is it possible to change the fortigate hostname and then also the NAS identifier on the NPS server? Will this impact anything else? Such as certs of other EAP settings? We are using EAP TLS with cert. for authentication.
Also how would you do this for two fortigates with two different hostnames? Can you add a second NAS identifier in NPS under EAP TLS properties and Connection request policies?
Thank you
Solved! Go to Solution.
The NAS Identifier is a RADIUS attribute. It will have an effect only if it is used in policy evaluation within NPS.
You can also change the hostname while keeping the same NAS identifier as shown in this article: Technical Tip: Configure NAS identifier for RADIUS
Hello c-j,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello c-j,
I found this solution. Can you tell us if it helps, please?
To change the hostname of your FortiGate and update the NAS identifier on the NPS server, follow these steps:
Change the FortiGate Hostname:
config system global
set hostname <new_hostname>
end
System -> Settings
and change the hostname.Update NAS Identifier on NPS Server: Ensure that the NAS identifier on the NPS server matches the new hostname of the FortiGate. This is crucial for the RADIUS server to identify the RADIUS client correctly.
Impact on EAP-TLS and Certificates: Changing the hostname and NAS identifier should not directly impact EAP-TLS or certificates, as these are typically based on the certificate's common name (CN) and not the NAS identifier. However, ensure that any certificate configurations or policies that rely on the hostname are updated accordingly.
Handling Multiple FortiGates:
Verification: After making these changes, verify the configuration by testing the RADIUS authentication to ensure that the NPS server correctly identifies and authenticates the FortiGates.
By following these steps, you can change the FortiGate hostname and update the NAS identifier without impacting your EAP-TLS authentication setup.
The NAS Identifier is a RADIUS attribute. It will have an effect only if it is used in policy evaluation within NPS.
You can also change the hostname while keeping the same NAS identifier as shown in this article: Technical Tip: Configure NAS identifier for RADIUS
Thanks a lot Emirjon!!
User | Count |
---|---|
2642 | |
1405 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.