FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rmetzger
Staff
Staff
Article Id 190844

Description
When selecting "Enable Endpoint NAC" on a FortiGate Firewall Policy, the following error message may appear "Cannot enable FortiClient checking because authentication is redirected to HTTPS".
Solution

The root cause is that the following option has been enabled (from the WEB based interface): 
User --> Options --> "Redirect HTTP Challenge to a Secure Channel(HTTPS)"
Disabling this option will allow Endpoint NAC checking.

The underlying reason is that the FortiClient cannot attach data to an HTTPS stream to the FortiGate for endpoint NAC checking.




Contributors