Home
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate 5000
FortiGate 6000
FortiGate 7000
FortiProxy
NOC & SOC Management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
FortiVoice Cloud
FortiRecorder
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
Flex-VM
Cloud Native Protection
FortiCNP
FortiDevSec
FortiGate CNF
Web Application / API Protection
FortiWeb
FortiWeb Cloud
FortiADC
FortiGSLB
SAAS Security
FortiMail
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiInsight
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
4-D Resources
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Hardware Guides
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAI
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiEdge
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
AscenLink
AV Engine
AWS Firewall Rules
Flex-VM
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiClient
FortiClient Cloud
FortiCloud Account Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDNS
FortiEDR
FortiExplorer
FortiExtender
FortiExtender Cloud
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGSLB
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR Cloud
FortiNDR Private Cloud
FortiNDR Public Cloud
FortiPAM
FortiPAM Private Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScan
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Managed FortiGate Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Documents
Library
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiProxy
NOC & SOC Management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
/
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
/
FortiVoice Cloud
FortiRecorder
/
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
Flex-VM
Cloud Native Protection
FortiCNP
FortiDevSec
FortiGate CNF
Web Application / API Protection
FortiWeb
/
FortiWeb Cloud
FortiADC
/
FortiGSLB
SAAS Security
FortiMail
/
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiInsight
/
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
/
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Curated links by solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
4-D Resources
Define, Design, Deploy, Demo
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Hardware Guides
Filter Products
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAI
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiEdge
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
Filter Products
AscenLink
AV Engine
AWS Firewall Rules
Flex-VM
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiClient
FortiClient Cloud
FortiCloud Account Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDNS
FortiEDR
FortiExplorer
FortiExtender
FortiExtender Cloud
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGSLB
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR Cloud
FortiNDR Private Cloud
FortiNDR Public Cloud
FortiPAM
FortiPAM Private Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScan
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Managed FortiGate Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Search documents and hardware ...
Version:
6.5.0
6.4.0
6.3.0
Version:
6.2.0
6.1.0
6.0.0
Version:
5.5.0
Table of Contents
EAP-TLS authentication
Wired 802.1x EAP-TLS with computer authentication
Active Directory prerequisites
Configuring the certificates
Manually importing the client certificate - Windows 10
Configuring the FortiAuthenticator AD server
Configuring the user group
Configuring remote user sync rules
Configuring the FortiAuthenticator RADIUS client
Configuring the switch
Results
Wireless 802.1x EAP-TLS with computer authentication
Active Directory prerequisites
Configuring the certificates
Manually importing the client certificate - Windows 10
Configuring the Intel PROSet Supplicant - Windows 10
Configuring the FortiAuthenticator AD server
Configuring the user group
Configuring remote user sync rules
Configuring the FortiAuthenticator RADIUS client
Configuring the FortiWiFi
Results
Wireless 802.1x EAP-TLS with user authentication
Configuring the certificates
Manually importing the client certificate - Windows 10
Configuring the FortiAuthenticator AD server
Configuring the user group
Configuring remote user sync rules
Configuring the FortiAuthenticator RADIUS client
Configuring the FortiWiFi
Results
FortiToken and FortiToken Mobile
FortiToken Mobile Push for SSL VPN
Adding a FortiToken to the FortiAuthenticator
Adding the user to the FortiAuthenticator
Creating the RADIUS client on the FortiAuthenticator
Connecting the FortiGate to the RADIUS server
Configuring the SSL VPN
Results
Guest Portals
FortiAuthenticator as Guest Portal for FortiWLC
Creating the FortiAuthenticator as RADIUS server on the FortiWLC
Creating the Captive Portal profile on the FortiWLC
Creating the security profile on the FortiWLC
Creating the QoS rule on the FortiWLC
Creating the ESS Profile on the FortiWLC
Creating FortiWLC as RADIUS Client on the FortiAuthenticator
Creating the Guest Portal on the FortiAuthenticator
Creating the Portal Rule on the FortiAuthenticator
Results
MAC authentication bypass
MAC authentication bypass with dynamic VLAN assignment
Configuring MAC authentication bypass on the FortiAuthenticator
Configuring the user group
Configuring the RADIUS client
Configuring the 3rd-party switch
Results
SAML authentication
SAML 2.0 FSSO with FortiAuthenticator and Centrify
Configuring DNS and FortiAuthenticator's FQDN
Enabling FSSO and SAML on the FortiAuthenticator
Adding SAML connector to Centrify for IdP metadata
Importing the IdP certificate and metadata on the FortiAuthenticator
Uploading the SP metadata to the Centrify tenant
Configuring FSSO on the FortiGate
Configuring captive portal and security policies
Results
SAML 2.0 FSSO with FortiAuthenticator and Google G Suite
Configuring FSSO and SAML on the FortiAuthenticator
Configuring SAML on G Suite
Importing the IdP certificate and metadata on the FortiAuthenticator
Configuring FSSO on the FortiGate
Configuring Captive Portal and security policies
Results
SAML 2.0 FSSO with FortiAuthenticator and Okta
Configuring DNS and FortiAuthenticator's FQDN
Enabling FSSO and SAML on the FortiAuthenticator
Configuring the Okta developer account IDP application
Importing the IDP certificate and metadata on the FortiAuthenticator
Configuring FSSO on the FortiGate
Configuring Captive Portal and security policies
Results
Self-service Portal
FortiAuthenticator user self-registration
Creating a self-registration user group
Enabling self-registration
Creating a new SMTP server
Results - Self-registration
Results - Administrator approval
VPNs
SSL VPN with RADIUS and FortiToken
Creating a user and a user group
Creating the RADIUS client
Connecting the FortiGate to FortiAuthenticator
Allowing users to connect to the VPN
Results
Legacy
Social WiFi captive portal
Social WiFi captive portal with FortiAuthenticator (Facebook)
Configuring the Facebook developer account API
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to Facebook
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Social WiFi captive portal with FortiAuthenticator (Form-based)
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Social WiFi captive portal with FortiAuthenticator (Google+)
Configuring the Google+ developer account API
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to Google
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Social WiFi captive portal with FortiAuthenticator (LinkedIn)
Configuring the LinkedIn developer account API
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to LinkedIn
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Social WiFi captive portal with FortiAuthenticator (Twitter)
Configuring the Twitter developer account API
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to Twitter
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Change log
Home
FortiAuthenticator 5.5.0
Cookbook
Cookbook
EAP-TLS authentication
Wired 802.1x EAP-TLS with computer authentication
Active Directory prerequisites
Configuring the certificates
Manually importing the client certificate - Windows 10
Configuring the FortiAuthenticator AD server
Configuring the user group
Configuring remote user sync rules
Configuring the FortiAuthenticator RADIUS client
Configuring the switch
Results
Wireless 802.1x EAP-TLS with computer authentication
Active Directory prerequisites
Configuring the certificates
Manually importing the client certificate - Windows 10
Configuring the Intel PROSet Supplicant - Windows 10
Configuring the FortiAuthenticator AD server
Configuring the user group
Configuring remote user sync rules
Configuring the FortiAuthenticator RADIUS client
Configuring the FortiWiFi
Results
Wireless 802.1x EAP-TLS with user authentication
Configuring the certificates
Manually importing the client certificate - Windows 10
Configuring the FortiAuthenticator AD server
Configuring the user group
Configuring remote user sync rules
Configuring the FortiAuthenticator RADIUS client
Configuring the FortiWiFi
Results
FortiToken and FortiToken Mobile
FortiToken Mobile Push for SSL VPN
Adding a FortiToken to the FortiAuthenticator
Adding the user to the FortiAuthenticator
Creating the RADIUS client on the FortiAuthenticator
Connecting the FortiGate to the RADIUS server
Configuring the SSL VPN
Results
Guest Portals
FortiAuthenticator as Guest Portal for FortiWLC
Creating the FortiAuthenticator as RADIUS server on the FortiWLC
Creating the Captive Portal profile on the FortiWLC
Creating the security profile on the FortiWLC
Creating the QoS rule on the FortiWLC
Creating the ESS Profile on the FortiWLC
Creating FortiWLC as RADIUS Client on the FortiAuthenticator
Creating the Guest Portal on the FortiAuthenticator
Creating the Portal Rule on the FortiAuthenticator
Results
MAC authentication bypass
MAC authentication bypass with dynamic VLAN assignment
Configuring MAC authentication bypass on the FortiAuthenticator
Configuring the user group
Configuring the RADIUS client
Configuring the 3rd-party switch
Results
SAML authentication
SAML 2.0 FSSO with FortiAuthenticator and Centrify
Configuring DNS and FortiAuthenticator's FQDN
Enabling FSSO and SAML on the FortiAuthenticator
Adding SAML connector to Centrify for IdP metadata
Importing the IdP certificate and metadata on the FortiAuthenticator
Uploading the SP metadata to the Centrify tenant
Configuring FSSO on the FortiGate
Configuring captive portal and security policies
Results
SAML 2.0 FSSO with FortiAuthenticator and Google G Suite
Configuring FSSO and SAML on the FortiAuthenticator
Configuring SAML on G Suite
Importing the IdP certificate and metadata on the FortiAuthenticator
Configuring FSSO on the FortiGate
Configuring Captive Portal and security policies
Results
SAML 2.0 FSSO with FortiAuthenticator and Okta
Configuring DNS and FortiAuthenticator's FQDN
Enabling FSSO and SAML on the FortiAuthenticator
Configuring the Okta developer account IDP application
Importing the IDP certificate and metadata on the FortiAuthenticator
Configuring FSSO on the FortiGate
Configuring Captive Portal and security policies
Results
Self-service Portal
FortiAuthenticator user self-registration
Creating a self-registration user group
Enabling self-registration
Creating a new SMTP server
Results - Self-registration
Results - Administrator approval
VPNs
SSL VPN with RADIUS and FortiToken
Creating a user and a user group
Creating the RADIUS client
Connecting the FortiGate to FortiAuthenticator
Allowing users to connect to the VPN
Results
Legacy
Social WiFi captive portal
Social WiFi captive portal with FortiAuthenticator (Facebook)
Configuring the Facebook developer account API
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to Facebook
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Social WiFi captive portal with FortiAuthenticator (Form-based)
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Social WiFi captive portal with FortiAuthenticator (Google+)
Configuring the Google+ developer account API
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to Google
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Social WiFi captive portal with FortiAuthenticator (LinkedIn)
Configuring the LinkedIn developer account API
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to LinkedIn
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Social WiFi captive portal with FortiAuthenticator (Twitter)
Configuring the Twitter developer account API
Configuring the social portal RADIUS service on the FortiAuthenticator
Configuring the FortiGate authentication settings
Configuring the FortiGate WiFi settings
Configuring the FortiGate to allow access to Twitter
Configuring the FortiGate to allow access to the FortiAuthenticator
Results
Change log
5.5.0
6.5.0
6.4.0
6.3.0
6.2.0
6.1.0
6.0.0
5.5.0
Download PDF
Copy Link
EAP-TLS authentication
This section describes configuring EAP-TLS authentication with FortiAuthenticator.
EAP-TLS authentication
This section describes configuring EAP-TLS authentication with FortiAuthenticator.
Link
PDF
TOC