Technical Tip: Users sharing the same switch port does not get the correct VLAN from NAC policy in an environment where EMS is configured to assign VLANs based on the EMS tag
Description | This article describes a practical issue observed in a solution where EMS and NAC have been used to identify users and assign VLANs based on the EMS TAG.
| |
Scope | FortiGate, FortiClient EMS. | |
Solution | As per the article Troubleshooting Tip: Resolving port flapping issues when FortiGate is configured with NAC policies the 'set match-type override' command is used to retain the matched devices' details. But this causes another issue as described above.
 Or it is possible to not use 'set match-type override' under NAC policy (Note: usage of this command is dependent on the solution used).
|
