Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Note: Network Access Policy for Wireless Not Putting Host on Expected VLAN

  • September 28, 2018
  • 0 replies
  • 942 views
Description
Network Access Policy for Wireless Not Putting Host on Expected VLAN

Solution

Issue:  Wireless client not being placed on the excpected VLAN, even though the correct Network Access Policy is matching, and RADIUS debug shows the proper VLAN being returned by Network Sentry.

Example:
RadiusServer accepting client 80-00-0b-bb-f1-10 for device 10.12.0.8 and policy 53 ptime=0:0:4:4:4:25

When Network Sentry returns a specific VLAN for the host that was "accepted," the controller will not put that host on that VLAN unless AAA-Override is enabled. This configuration is per SSID.

Solution:  Enable the AAA-Override setting on the wireless controller for the SSID.


Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!