Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Tip: Troubleshooting location based Network Access policies

  • September 28, 2018
  • 0 replies
  • 1753 views

Description

 

This article describes the following symptoms:

  • The registered host not getting an IP address from the correct production network.
  • The host does not match the correct network access policy.  This can be validated in Hosts > Host View.  (Right click on host record and select Policy Details.  Host must be online for accurate results).
  • The host is assigned the default VLAN (this occurs when host does not match any network access policy).

One of the most common reasons why hosts do not match a location based network access policy is
because the switch/port/SSID/AP has not been added to the location group in the user host profile.

 

Scope

 

FortiNAC.


Solution

 

Add the switch/port/SSID/AP to the location group:
  1. Navigate to Policy > Policy Configuration.
  2. Select Network Access.
  3. Select the Network Access Policy and click Modify.
  4. Select the Modify icon for the User/Host profile (pencil and paper).
  5. Next to the Where (Location): field, click the Select... button.
  6. If the appropriate location group is already under Selected Groups, click on the group and click Modify Group and add the switch/port/SSID/AP.  
  7. Select OK to save changes.

Review Policy Details in Host View to validate the host matches the policy.

 

Related article:

Troubleshooting Tip: VLANs not changing on a wired switch