Skip to main content
Staff & Editor
December 24, 2024

Technical Tip: Groups imported in FortiNAC does not show any Members listed

  • December 24, 2024
  • 0 replies
  • 1552 views
Description This article describes that LDAP Groups imported to FortiNAC do not show any members listed.
Scope FortiNAC, FortiNAC-F.
Solution

After importing LDAP groups into FortiNAC, the Group members under System -> Groups show as '0' (Zero), once a host is registered as a User 'Reg to User' in Hosts view with a domain user account. The members' values will change.

LDAP_groups_members_after_user_authentication(1).PNG

 

With dot1x Machine/computer Authentication (FortiNAC-F), the Host is 'Reg as Device', and even after dot1x User Authentication the authenticated machine will remain as 'Reg as Device'.

Even though the Members value remains '0' FortiNAC will still leverage from LDAP groups in the User/host Profiles, but the user will not appear as a member under System -> Groups (This is an expected behavior).


Capture123.JPG

 

After FortiNAC automatically imports LDAP groups under System -> Groups, the Group Member Type: Host. (The Group member type will show as Host).

The behavior of Technical Tip: FortiNAC v7.6 LDAP group membership based on 'User' or 'Device' type Registration has slightly changed starting from version 7.6.x and above.
 

Related articles:
Technical Tip: What causes a host to be moved to an imported LDAP Host Group

Technical Tip: FortiNAC v7.6 LDAP group membership based on 'User' or 'Device' type Registration

Technical Tip: Role assignment order
Technical Tip: Using the same host to dynamically change network policies via ‘logged on user’ from LDAP roles
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!