SecureW2 extends certificate-based trust into your Fortinet environment, delivering phishing-resistant passwordless access backed by a proven PKI foundation. Deploy Certificate Distribution for SSL Inspection to manage encrypted traffic, maintain complete network visibility, and enforce identity policies across every managed and BYOD device, without disruption.
Overview
SecureW2 is the PKI and RADIUS layer for Fortinet environments. It issues device-bound, phishing-resistant certificates to every device and automatically distributes them via JoinNow self-service onboarding. Because FortiGate cannot accept EAP-TLS certificate authentication directly over RADIUS today, SecureW2 closes the gap in two ways: integrate the SecureW2 certificate authority directly into FortiGate to establish a certificate chain of trust, or run JoinNow Cloud RADIUS with a policy that evaluates identity, role, and live device posture, layering MFA through SAML. JoinNow Managed PKI manages the full certificate lifecycle, and certificates can be revoked in real time the moment an IdP, MDM, or EDR flags a device as risky. When Fortinet adds native EAP-TLS-over-RADIUS support, your PKI infrastructure is already in place.
How It Works
The device presents its certificate to the Fortinet VPN gateway, which forwards the request to Cloud RADIUS using RADIUS. Cloud RADIUS validates the certificate and performs a live identity provider lookup to confirm the userβs status and group membership. It returns a RADIUS Accept to the gateway, which establishes the encrypted tunnel. A deprovisioned user is blocked on subsequent connection attempts without certificate revocation.
JoinNow automates SSL inspection certificate distribution across Windows, macOS, iOS, Android, and ChromeOS through self-service onboarding. Devices receive and trust the Fortinet inspection certificate automatically, eliminating browser warnings and manual installation across managed and BYOD fleets.
Organizations running WPA2-Enterprise on Fortinet often depend on on-premises NPS servers and Active Directory Certificate Services to authenticate devices. SecureW2 eliminates that infrastructure dependency. Cloud RADIUS authenticates directly against the configured identity provider: no NPS, no domain controller, no AD CS in the path.
Β
During enrollment, the Policy Engine validates user identity before issuing a certificate. At authentication time, Cloud RADIUS performs a live identity provider lookup, verifying account status and group membership, and returns the appropriate RADIUS response to Fortinet. The full path runs through Cloud RADIUS and the identity provider, not on-premises infrastructure. NPS and AD CS can be decommissioned without affecting Wi-Fi or VPN access.
Β
Branch offices and remote users authenticate the same way.Β Because the authentication path runs through Cloud RADIUS rather than on-premises servers, there is no dependency on domain controller reachability, VPN tunnels to reach NPS, or AD replication health.
Cloud RADIUS reads identity provider group membership at authentication time and maps group values to RADIUS policy attributes, including VLAN assignments. Each rule specifies a group condition and the RADIUS attributes to return when that condition is met.
Β
Group-to-VLAN rules are defined once in Cloud RADIUS. Identity provider group management automatically drives network access. When a user moves between groups, the change takes effect at the next authentication event, no manual RADIUS policy changes required.
Frequently Asked Questions
Most organizations can configure the integration in a single session by following our setup guide and working with our knowledgeable engineers. Once complete, users begin authenticating with certificates instead of passwords without requiring major changes to existing Fortinet configurations.
Unlike WiβFi enterprise networks, many VPNs, including Fortinet's, do not yet support EAPβTLS certificate authentication natively over RADIUS. To address this, SecureW2 provides two pathways. With Cloud RADIUS and MFA, VPN sessions can be authenticated via SAML, with users assigned a unique username and password and automatically prompted for MFA. Alternatively, with SecureW2 Managed PKI, organizations can integrate our certificate authorities directly into their firewall, establishing a certificate chain of trust without relying on EAPβTLS. Both methods give administrators flexible, secure options for removing traditional passwords from the VPN login process.
From the user's perspective, connecting to Fortinet with SecureW2 is seamless; users simply launch FortiClient (or attempt a connection) and are authenticated automatically via client certificate. The difference is behind the scenes: instead of typing a username or password, the session is authenticated automatically with a certificate issued to their device. This creates a frictionless login experience where users connect instantly and securely, without having to remember or reset passwords.
SecureW2 continuously manages the full lifecycle of VPN certificates. If a device is reported lost, stolen, or flagged by endpoint security tools, its certificate is revoked using cloudβbased PKI controls. Administrators can choose to suspend it temporarily (with the option to restore later) or revoke it fully, which updates the CRL and blocks VPN access. This minimizes exposure while giving IT teams flexible control to reinstate secure access once the device is remediated.
Currently, Fortinet cannot accept EAPβTLS certificate authentication directly over RADIUS. SecureW2 provides two integration paths: using Cloud RADIUS with MFA to secure VPN logins with an identityβbound, MFAβprotected credential, or deploying Managed PKI to establish a certificate trust chain within Fortinet firewalls. Both methods provide strong security today and ensure that when Fortinet adds EAPβTLS support in the future, your organization will already have the full PKI infrastructure in place.
Connect with our integration specialists to implement this solution in your environment and transform your security posture.