authenticates the switch port (or the wireless AP): until the device proves its identity, the port only passes EAP traffic to the server (FAC here). On success the port opens, and a VLAN can even be assigned dynamically by group.
Supplicant, authenticator (FortiSwitch/FortiAP) and RADIUS server. Until authentication succeeds only EAP passes — no DHCP, no IP. EAP-TLS uses an AD CS certificate; PEAP sends the AD password inside a TLS tunnel and is Evil Twin bait if the client does not validate the server certificate. Result: dynamic VLAN by AD group or a guest VLAN; MAB for printers relies on a spoofable MAC.
Related topics in this course
- issues the certificates; a bad template means both ESC1 and broken .
- /NBT-NS poisoning — limits who even reaches the same layer 2 segment.
- Tiering — a dynamic VLAN by group is the physical boundary between tiers.
Choosing the EAP method
- PEAP-MSCHAPv2 — the client authenticates with domain credentials inside a TLS tunnel. Simple and universal, but…
- — the client presents a device certificate issued by . No passwords over the air at all.
This ties directly to the lessons: for you create a workstation certificate template with autoenrollment — a domain machine is 802.1X-ready as soon as it enrols.
Fortinet's role: FAC is the server validating the certificate or account and returning the VLAN attribute (Tunnel-Private-Group-ID); FortiGate manages FortiSwitch and configures port centrally.
Lab practice
- In create a Workstation-Auth template based on Workstation Authentication with autoenrollment and Client Authentication, then enable it in : Computer Configuration → Policies → Windows Settings → Security Settings → Public Key Policies → Autoenrollment.
- On FAC: Authentication → Service → Policy → New. Client — the switch or AP; method — (or if required); subject — the group CN=Workstations; reply attributes — Tunnel-Type=VLAN, Tunnel-Medium-Type=802, Tunnel-Private-Group-ID=<VLAN ID>.
On the client: confirm the machine certificate exists (certlm.msc) and configure wired via — Computer Configuration → Policies → Windows Settings → Security Settings → Wired Network, with server certificate validation on and your CA root trusted. Verify: an unauthenticated port is dead except for EAP, and after success the right VLAN is assigned.
Risks and detection
- Rogue AP + = stolen domain credentials. Detection: bursts of failed from one location, reports of a suspicious Wi-Fi, new certificates on the network. Prevention: .
- Guest VLAN as a loophole: if failure drops the client into an internet-capable guest VLAN, an attacker just waits for the timeout. The guest VLAN must be genuinely isolated.
- (MAC Authentication Bypass) for printers is a bypass — a MAC is trivial to spoof. Put printers in a separate VLAN with ACLs and use MAB sparingly.
- FAC logs every attempt; a rule like "more than N failures per port per minute → shut the port" is a ready-made brute-force detection.
Mitigation
- Prefer only; machine certificates rather than user certificates.
- Enforce strict server certificate validation on clients via , never by hand.
- Keep the guest VLAN isolated, with no routes to servers.
- Monitor FAC logs: failed authentications per port.