Technical Tip: FortiNAC-F v7.2.X replaces a radius disconnect message with a ‘bounce-port’ VSA attribute
| Description | This article describes how to change a 'radius disconnect message' to a 'bounce-port' VSA radius attribute in radius-accept messages. |
| Scope | FortiNAC-F v7.2.X |
| Solution | V7.2.X contains a global option that can change the message from a disconnect to a CoA, but attributes are not user-configurable (no option to configure additional RFC5176 Radius attributes).
The global option will instruct the code to create a system-defined CoA request. To configure the global option, execute these commands in the CLI of FortiNAC-F:
execute enter-shell globaloptiontool -name radiusServer.use.coa.for.disconnect -set true
PCAP file before applying the global option:
output.master debugs:
attributes = 1f 13 63 63 2d 39 36 2d 65 35 2d 64 36 2d 36 63 2d 33 37
After applying the global option:
PCAP radius packet details:
RADIUS Protocol |
