Skip to main content
AD Academy
Network security: Fortinet
Advanced18 minLast updated: Topic 11 of 14

802.1X and NAC — only authenticated devices get in

Port-level authentication, EAP-TLS vs PEAP, dynamic VLAN assignment and the Evil Twin trap.

Not read

What you will learn here

  • Related topics in this course
  • Choosing the EAP method
  • Lab practice

Worth reading first:FortiAuthenticator — RADIUS, TACACS+ and MFA with AD

authenticates the switch port (or the wireless AP): until the device proves its identity, the port only passes EAP traffic to the server (FAC here). On success the port opens, and a VLAN can even be assigned dynamically by group.

Supplicant, authenticator (FortiSwitch/FortiAP) and RADIUS server. Until authentication succeeds only EAP passes — no DHCP, no IP. EAP-TLS uses an AD CS certificate; PEAP sends the AD password inside a TLS tunnel and is Evil Twin bait if the client does not validate the server certificate. Result: dynamic VLAN by AD group or a guest VLAN; MAB for printers relies on a spoofable MAC.

Short and clear

  • Until authentication succeeds the port passes only EAP — no DHCP, no IP address.
  • EAP-TLS uses an AD CS certificate; PEAP sends the AD password inside a TLS tunnel.
  • PEAP without server certificate validation on the client is an open door for Evil Twin hash theft.
  • After success a dynamic VLAN can be assigned by AD group; MAB for printers is an exception to monitor.

Real-life example802.1X goes live and the printers stop working. The right fix is MAB in a tight, monitored VLAN — not disabling 802.1X across the switch.

Related topics in this course

  • issues the certificates; a bad template means both ESC1 and broken .
  • /NBT-NS poisoning — limits who even reaches the same layer 2 segment.
  • Tiering — a dynamic VLAN by group is the physical boundary between tiers.

Choosing the EAP method

  • PEAP-MSCHAPv2 — the client authenticates with domain credentials inside a TLS tunnel. Simple and universal, but…
  • — the client presents a device certificate issued by . No passwords over the air at all.

This ties directly to the lessons: for you create a workstation certificate template with autoenrollment — a domain machine is 802.1X-ready as soon as it enrols.

Fortinet's role: FAC is the server validating the certificate or account and returning the VLAN attribute (Tunnel-Private-Group-ID); FortiGate manages FortiSwitch and configures port centrally.

Lab practice

  • In create a Workstation-Auth template based on Workstation Authentication with autoenrollment and Client Authentication, then enable it in : Computer Configuration → Policies → Windows Settings → Security Settings → Public Key Policies → Autoenrollment.
  • On FAC: Authentication → Service → Policy → New. Client — the switch or AP; method — (or if required); subject — the group CN=Workstations; reply attributes — Tunnel-Type=VLAN, Tunnel-Medium-Type=802, Tunnel-Private-Group-ID=<VLAN ID>.
config switch-controller 802-1X-settings
    set link-down-flush enable
end

config switch-controller managed-switch
    edit <FortiSwitch-ID>
        config ports
            edit "port5"
                set 802-1X enable
                set security-mode 802.1X
            next
        end
    next
end
bash

On the client: confirm the machine certificate exists (certlm.msc) and configure wired via — Computer Configuration → Policies → Windows Settings → Security Settings → Wired Network, with server certificate validation on and your CA root trusted. Verify: an unauthenticated port is dead except for EAP, and after success the right VLAN is assigned.

Risks and detection

  • Rogue AP + = stolen domain credentials. Detection: bursts of failed from one location, reports of a suspicious Wi-Fi, new certificates on the network. Prevention: .
  • Guest VLAN as a loophole: if failure drops the client into an internet-capable guest VLAN, an attacker just waits for the timeout. The guest VLAN must be genuinely isolated.
  • (MAC Authentication Bypass) for printers is a bypass — a MAC is trivial to spoof. Put printers in a separate VLAN with ACLs and use MAB sparingly.
  • FAC logs every attempt; a rule like "more than N failures per port per minute → shut the port" is a ready-made brute-force detection.

Mitigation

  • Prefer only; machine certificates rather than user certificates.
  • Enforce strict server certificate validation on clients via , never by hand.
  • Keep the guest VLAN isolated, with no routes to servers.
  • Monitor FAC logs: failed authentications per port.

Check yourself

What is the state of the switch port before successful 802.1X authentication?

Why is EAP-TLS safer than PEAP-MSCHAPv2?

How does a rogue access point steal credentials with PEAP?

Why can a guest VLAN be dangerous on authentication failure?

Was this page helpful?