Technical Tip: Rogue wireless clients cannot connect to SSID
Description
Rogue wireless clients cannot connect to SSID. Registered clients connecting to the SSID work as expected.
Scope
ForiNAC v9.x.
Solution
- Navigate to Network > Inventory.
- Select the Controller/Access Point, then click on the SSIDs tab.
- Select the affected SSID, 'right-click' and select SSID Configuration.
If Registration State=Deny, FortiNAC rejects a RADIUS request that comes from a rogue host.
If Registration State= Enforce, but a VLAN is not defined (Registration Access Value= (none)), FortiNAC will reject the client (even if the RADIUS server accepts the user account).
Set the access value to the appropriate VLAN and select Apply. Registration State= Enforce.
Registration Access Value= (Registration VLAN)

Registration Access Value= (Registration VLAN)

