Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Elemanzer
New Contributor

Enterprise WPA2 issue with encryption and cert

I want to use enterprise wpa2 with the FSSO sign-on I' m using the public SSL cert for my wifi. When I connect to the wifi it says my " Windows can' t verify the server' s identity" The thumbprint is from my public cert I also can only connect if I use unencrypted PAP. Is there any other way? I could use a Radius server, but then I can see who the user is.
2 REPLIES 2
Dave_Hall
Honored Contributor

The error message relates to the validation of the server certificate. If the server does not have valid cert then the " Validate server certificate" option (somewhere in the wireless network settings) can be unchecked. Internally, our company does not use FSSO, but do use Enterprise WPA2 on our field tech (Windows 7-based) laptops. Instructions for configuring the wifi on them is similar to the following....
 1. In Network and Sharing Center click on Manage wireless networks
 2. Click Add
 3. Choose Manually create a network profile
 4. For Network name enter COMPANYNAME
 5. For Security type choose WPA2-Enterprise
 6. Click Next
 7. Click " Change Network Connection settings"  if offered (otherwise from the Manage wireless networks menu right-click COMPANYNAME and choose Properties)
 8. Click the Security tab
 9. Make sure Microsoft: Protected EAP (PEAP) is set for authentication method then click Settings
 10. Uncheck Validate server certificate
 11. Make sure Secure password (EAP-MSCHAP V2) is set for Authentication Method then click Configure
 12. Uncheck Automatically use my Windows login name and password
 13. Click OK
 14. Click OK
 15. Click Advanced settings
 16. Check Specify authentication mode then choose User Authentication
 17. Click Save (or replace) credentials
 18. For username enter the COMPANYNAME domain name followed by a backslash then your Domain username. (e.g. COMPANYNAME\user)
 19. For password use your COMPANYNAME ID password.
 20. Click OK
 21. Click OK
 22. Click OK
But YMMV.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Elemanzer

Didn' t work, the cert error went away, but it still requires PAP.
Labels
Top Kudoed Authors