Controllerless Networks

 View Only
last person joined: yesterday 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

AP 505 Instant + Radius throught Fortinet Firewall

This thread has been viewed 19 times
  • 1.  AP 505 Instant + Radius throught Fortinet Firewall

    Posted 29 days ago

    Hello,

    I'm managing Many Cluster of AP 505 on the local Network and everything works fine. We use EAP TLS with a NPS server (Radius on Windows Server 2019).

    We also havesome remote sites on which we'd like to deploy some APs.  theses remote sites connect to the main Network with a IPSec Tunnel (Zyxel on the remote sites and Fortinet 101F on the HQ site).

    The problem is that on the remote sites we can't connect to the SSID. The logs on the NPS server show that the AP connect to the Radius but it looks like the "packet" don't come back to the AP and the client.

    The firewalls on both sides are ok.

    I've check the configuration of the NPS, the AP configuration, etc... but i don't find anything and don't how to solve my problem. 

    Any idea?

    Regards,

    David



  • 2.  RE: AP 505 Instant + Radius throught Fortinet Firewall

    EMPLOYEE
    Posted 29 days ago

    If you are using EAP-TLS then there is a possibility that you'll need to force EAP fragmentation for the authentication to work properly.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: AP 505 Instant + Radius throught Fortinet Firewall

    Posted 28 days ago

    Hi,

    I've tried to redue the MTU on the NPS and AP but it doesn't change anything.

     

     

     

    Bien cordialement,

     

    David STRAPPAZON
    Administrateur systèmes et réseaux
    Direction des Systèmes d'Information et du Numérique

    internet copie

    www.chateaurenard.com

    04 90 24 35 35

    06 12 55 39 36

     

     






  • 4.  RE: AP 505 Instant + Radius throught Fortinet Firewall

    EMPLOYEE
    Posted 28 days ago

    https://www.arubanetworks.com/techdocs/CLI-Bank/Content/instant/dot1x%20eap-frag-mtu.htm

    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/cc755205(v=ws.10)



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: AP 505 Instant + Radius throught Fortinet Firewall

    Posted 23 days ago

    Hello,

    Thank a lot for your help!

    i wasn't aware of tha eap-frag-mtu command.

    Now everything works fine!

    Regards,

    David