Skip to main content
sfernando
Staff
Staff
January 28, 2026

Technical Tip: Important commands to collect when NAC policy does not assign correct VLAN to users

  • January 28, 2026
  • 0 replies
  • 337 views
Description This article describes what commands are needed to collect when users are assigned incorrect VLANs in the NAC policy environment.
Scope FortiGate, EMS, NAC.
Solution

In a complex network environment where FortiGate, FortiSwitch, EMS, and NAC policies are involved, it is observed that users are not assigned the correct VLAN. In such cases, troubleshooting the issue is tricky due to the dynamic nature of the issue.

 

It is important and very useful to collect the output of the commands below to get a better idea of the issue.

 

diagnose switch-controller mac-device cache
diagnose switch-controller mac-device nac onboarding
diagnose switch-controller mac-device nac known
diagnose switch-controller mac-cache show
diagnose user-device-store device memory list

 

Output of the above will look as follows:

 

111111.jpg

 

22222222222222222.jpg

 

33333333333333333333.jpg

 

44444444444.jpg

 

555555555.jpg