Skip to main content
scitlak
Staff
Staff
August 17, 2025

Technical Tip: How to send CoA re-authentication request to Cisco WLC

  • August 17, 2025
  • 0 replies
  • 915 views
Description This article describes how to configure FortiNAC to send a custom CoA request to Cisco WLC for re-authentication.
Scope FortiNAC -F 7.4, FortiNAC -F 7.6.
Solution

In some circumstances, while Cisco WLC receives a CoA disconnect (RFC 5176) message, Cisco WLC disconnects the host; however, it does not send any new RADIUS authentication requests for the same host. In these circumstances, FortiNAC can be configured to send a CoA Re-Authentication request with the required RADIUS VSA.

 

  1. Create a new RFC Attribute group under Network -> RADIUS -> Attribute Groups by using the Cisco RADIUS VSAs below. In addition to the Cisco VSAs shown below, add the 'Calling-Station-id' attribute as a session identifier that is required by Cisco.

Cisco:Avpair=“subscriber:command=reauthenticate”
Cisco:Avpair=“subscriber:reauthenticate-type=rerun”


04.08.2025_15.08.00_REC.png

 

  1. Navigate to SSID configuration and change the RFC5176 Mode to Custom and select the RFC5176 Attribute Group for the newly created RFC Group.


04.08.2025_15.13.35_REC.png

 

  1. Create a circumstance so that FortiNAC can send a CoA Disconnect message, like Guest Self-Registration, and test the CoA disconnect message.


04.08.2025_15.15.54_REC.png

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!