cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
15318
Views
16
Helpful
12
Replies

Cisco ISE and Fortinet

Davion Stewart
Level 1
Level 1

Good day, 

 

Is there any official support for integrating ISE with fortigate/FortiAPs?

 

Want to know the possibility of using ISE as the RADIUS server to authenticate wireless users using fortiAPs. 

 

 

1 Accepted Solution

Accepted Solutions

Timothy Abbott
Cisco Employee
Cisco Employee

It depends on how you want them to integrate with ISE.  ISE is a standards-based RADIUS server.  Chances are good that basic 802.1X authentication will work.  However, if you are looking to integrate for use cases such as BYOD then you will most likely have to figure out if they support RADIUS CoA and URL-Redirect.  You can also explore using a NAD profile.

 

Regards,

-Tim

View solution in original post

12 Replies 12

Timothy Abbott
Cisco Employee
Cisco Employee

It depends on how you want them to integrate with ISE.  ISE is a standards-based RADIUS server.  Chances are good that basic 802.1X authentication will work.  However, if you are looking to integrate for use cases such as BYOD then you will most likely have to figure out if they support RADIUS CoA and URL-Redirect.  You can also explore using a NAD profile.

 

Regards,

-Tim

Oh ok thanks alot for the reply. 

 

That's some good information

Do you know if there are any official documentation to refer to customers that are interested in doing this type of integration.

 

Ok cool thanks alot. 

 

Will check the links.

We don’t have anything specific for integrating the two systems. Are official documentation on ISE and RADIUS standards can be found in the ISE compatibility matrix.

Regards,
-Tim

Got you,

 

thanks much for the reply. 

did you ever get this to work?

I am also curious if you ever got this to work and what dictionary set you used? 

Hi guys,

 

Unfortunately i was unable to configure/test out this kind of implementation. Has anyone been able to?

After working with TAC and fortinet support I was able to get this to work for 802.1x authentications. 

Hi AdamF1,I wish you are very well.


Could you share the configuration that was done so that everything works correctly.


I thank you

 

 

Create a new device profile for Fortinet controller and apply the appropriate protocols and conditions to 802.1x and MAB.

-MAB- IEEE 802.11 and call check

-802.1x- IEEE 802.11

 

Build out the controller in network devices and apply the profile.

 

Depending on your policies you may need to build out a new one that sits above it as authentication may continue to try and use it and fail. You can make it unique by setting it to something like call-station id ( mac address of controller), this way only devices utilizing it will hit the policy. Just be careful when editing your global policy sets and conditions you create as you could impact your current authentications.