Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Tip: VLANs Not Switching When Role is Manually Changed

  • September 28, 2018
  • 0 replies
  • 1051 views

Description

 

This article discusses an issue when Host does not change VLANs after manually changing the Host or User role.  Policy Details in Host View show the correct Network Access Policy for the newly selected role, but the Host does not get switched to the new VLAN.  Switching from isolation to production works as expected.

Scope
 

FortiNAC, Network Sentry 7 and 8.


Solution

 

This could occur if the format used in the Configuration for the Network Access Policy is not the same as what's reflected in the wireless controller/Access Point's Model Configuration.

Example:
Model Configuration lists names (staff, student, etc).  This is the format read from the wireless controller/Access Point.
However, the Network Access Policy Configuration assigns VLAN IDs (70, 71, etc).

Network Sentry will not try to switch a VLAN if it is believed the currently assigned VLAN was not assigned by Network Sentry.  Upon changing a role in a registered Host record, Network Sentry will evaluate the Host.  Inconsistent formats between what is read from the controller/AP and the Network Access Policy's Configuration can cause the logic to incorrectly conclude that the VLAN was manually configured.  Consequently, the VLAN will not be changed.

Solution: When creating Network Access Configurations, always use the same VLAN format shown in the applicable controller/AP's Model Configuration. This will avoid unexpected VLAN switching behavior.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!