FortiNAC-8.x-WiFi 802.1X Based Network Using FortiNAC Local RADIUS Server
FortiNAC-8.x-WiFi 802.1X Based Network Using FortiNAC Local RADIUS Server
FORTINET BLOG
https://blog.fortinet.com
NSE INSTITUTE
https://training.fortinet.com
FORTIGUARD CENTER
https://fortiguard.com/
FEEDBACK
Email: [email protected]
Overview 4
Procedure - FortiGate 5
FortiGate – RADIUS configuration 5
FortiGate – SSID 6
FortiGate – Interfaces 7
Procedure - FortiNAC 9
FortiNAC – Enable the local RADIUS 9
FortiNAC – Certificate 9
FortiNAC – SSID configuration for using local RADIUS 10
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 3
Fortinet Technologies Inc.
Overview
Overview
This document provides guidance on creating a WiFi 802.1X based network using FortiNAC Local RADIUS
server. The procedure will be divided into two sections. The first section will address the FortiGate related
instructions while the second section will address the FortiNAC related instructions.
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 4
Fortinet Technologies Inc.
Procedure - FortiGate
Procedure - FortiGate
1. Navigate to User & Authentication > RADIUS Servers. Select Create New
2. Enter the following inputs for each field:
Name: FortiNAC
NAS IP: 192.168.200.1
Primary Server > IP/Name: 192.168.200.7
Primary Server> Secret: The same Secret set on FortiNAC
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 5
Fortinet Technologies Inc.
Procedure - FortiGate
FortiGate – SSID
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 6
Fortinet Technologies Inc.
Procedure - FortiGate
2. Under Wifi Settings, enable Security mode using RADIUS Server for Authentication with FortiNAC as the
Radius Server.
FortiGate – Interfaces
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 7
Fortinet Technologies Inc.
Procedure - FortiGate
i. Note: Set the DHCP to be a relay pointing to FortiNAC ETH1 for the Registration/Isolation VLAN
b. Client VLAN like for instance staff and students as needed (in the example, it is VLAN 242)
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 8
Fortinet Technologies Inc.
Procedure - FortiNAC
Procedure - FortiNAC
FortiNAC – Certificate
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 9
Fortinet Technologies Inc.
Procedure - FortiNAC
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 10
Fortinet Technologies Inc.
Procedure - FortiNAC
FortiNAC 8.x WiFi 802.1X based network using FortiNAC Local RADIUS Server 11
Fortinet Technologies Inc.
Copyright© 2020 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., in
the U.S. and other jurisdictions, and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company names may be
trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and
other results may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding
commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s
General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such
event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be
limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. In no event does Fortinet make any commitment related to future deliverables, features or
development, and circumstances may change such that any forward-looking statements herein are not accurate. Fortinet disclaims in full any covenants, representations, and
guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most
current version of the publication shall be applicable.