Skip to main content
tyang
Staff
Staff
July 13, 2026

Technical Tip: Preparing information before contacting Fortinet Support for FortiNAC

  • July 13, 2026
  • 0 replies
  • 102 views

Description

This article describes the information to collect before opening a FortiNAC Technical Assistance Center (TAC) support case. Providing complete environment details, logs, packet captures, and reproduction steps helps TAC begin the investigation more efficiently.

Scope

FortiNAC CentOS and FortiNAC-F.

Solution

Explore self-help resources:

Many common questions can be answered using these free resources:

  • Fortinet Community Knowledge Base. Hundreds of technical tips and how-to articles written by Fortinet engineers. See the Knowledge Base FortiNAC-F.

  • Fortinet Official Documentation. Admin Guides, Reference Manuals, Release Notes, and Deployment Guides for every version. Available at Fortinet Document Library FortiNAC-F.

  • Fortinet Video Library. Step-by-step video walkthroughs for common FortiNAC configurations and deployments. Available at NSE Certification Program.

  • FortiGuard Labs. Security advisories, threat intelligence, and vulnerability information. Available at FortiGuard Labs PSIRT Advisories.

 

Popular FortiNAC KB articles:


Services Outside of a Standard Support Case:

Some requests fall outside the scope of a standard TAC support case and are handled through separate service offerings:

  • FortiCare Professional Services (separate purchase). 

For new implementations, migrations, and design or planning engagements. Professional Services assists with designing, deploying, and optimizing the FortiNAC infrastructure.

What TAC Support does not cover:

  1. Hypervisor migrations (for example, VMware to Nutanix, VMware to Hyper-V, or KVM to VMware). These require Professional Services. For a self-guided approach, example Technical Tip: FortiNAC-F 7.2.x migration from VMware to Nutanix VMware to Nutanix Migration.

  2. CentOS to FortiNAC-F (FNAC-OS) migration from legacy v9.x to FortiNAC-F v7.2.x+. The documented procedures are available:

  3. Standalone migration: Technical Tip: How to Migrate a Standalone CentOS FortiNAC to FortiNAC-OS from version 9.X to FortiNAC-F v7.2.5 GA

  4. Upgrade to labeled software: Technical Tip: How to upgrade CentOS FortiNAC 9.X.X to FortiNAC-F labeled software

  5. HA migration notes:

To engage Professional Services, contact the Fortinet Sales representative or partner.

  • Advanced Services (separate purchase). 

For in-depth investigations beyond standard support, including Root Cause Analysis (RCA), upgrade planning, and architecture reviews. Contact the Fortinet Sales representative to purchase.

  • Managed FortiGate Service (separate purchase). 

For onboarding new equipment using Fortinet security best practices and ITIL methodologies, including deployment, configuration validation, incident response, and proactive security management. Contact the Fortinet Sales representative to purchase.

  • FortiConverter Service (one-time license, separate purchase). 

For configuration conversion and migration between FortiNAC models or from third-party vendors (for example, Cisco ISE to FortiNAC). Requires a paid license. Cases can be submitted through the FortiConverter Service Portal.

  • FortiGuard Security Advisory and Incident Response (separate purchase). 

For forensic analysis and incident response, not limited to Fortinet products. Contact the Fortinet Sales representative to purchase.


Before opening a case:

  • Active support contract is required. A valid support contract must be in place for the FortiNAC appliance serial number and any related Fortinet Fabric products (FortiGate, FortiAP, FortiSwitch, FortiManager, FortiAnalyzer). Verify entitlement at the Fortinet Support : go to Product List, select the product serial number, then select Entitlement.

  • Separate cases for Fabric products. If the issue involves multiple Fabric products, open a separate case for each product. This ensures the right subject matter experts are assigned to each component.

  • Firmware within the product life cycle. The FortiNAC appliance must be running a firmware version within its Product Life Cycle. End-of-Life (EoL) or End-of-Engineering (EoE) versions receive limited support.

  • Feature requests. If looking for a feature that does not yet exist, this is considered a New Feature Request (NFR) and is not handled through a support case. Submit NFRs through the local Fortinet Sales representative.

  • Third-party products. When third-party products or services are involved (ISPs, upstream or downstream routers, firewalls, virtual machines, PBX or VoIP, cloud infrastructure, servers, endpoints), the investigation is conducted from the perspective of FortiNAC and the Fortinet Fabric.

  • Be prepared to collaborate. Have the network administrator available to provide debug output, packet captures, configuration details, and to run diagnostic commands during the investigation. Including all relevant stakeholders early speeds up resolution.

  • One issue per case. Each support case should address a single technical issue. If there are multiple unrelated problems, open separate cases for each.

  • Review release notes before upgrading. Before upgrading FortiNAC, review the Release Notes for the target version. Check for changes to features relied upon and review the list of resolved and known issues.

  • Lost MFA or FortiToken. If access to the admin account is lost due to a lost FortiToken or MFA device, Fortinet Support cannot recover access. Fortinet Support does not hold super-admin credentials and cannot bypass MFA or password protection. Follow the recommended steps before enabling MFA on the primary admin account. See FortiToken 2FA Recovery Steps.

  • Moving licenses between appliances. To transfer endpoint licenses or other entitlements from one FortiNAC serial number to another (for example, during a hardware refresh or RMA replacement), open a case with Customer Service through the Fortinet Support Portal. TAC Support cannot process license transfers. For CentOS to FNAC-F migrations specifically, see Transfer Endpoint License Entitlements.


Describe the problem clearly:

Include the following in the case description:

  • What was expected to happen.

  • What actually happened.

  • When the problem began (date, time, and timezone).

  • Whether anything changed recently (upgrade, configuration change, network change, new devices added).

  • Whether the issue is constant or intermittent.

  • How many users or endpoints are affected.

  • Whether the issue can be reproduced, and if yes, the steps to reproduce.


Provide environment details:

Run this command from the CLI and include the output:

get system status


Also provide:

  • FortiNAC version and build (for example, FortiNAC-F v7.6.2 build 0123).

  • Appliance model and deployment type (standalone, HA pair, Manager, and Agents).

  • Hypervisor (VMware ESXi, KVM, Hyper-V, Nutanix AHV, AWS, Azure).

  • License type and licensed endpoint count.

  • Managed FortiGate models and firmware versions (if applicable).

  • A brief network overview indicating which interfaces serve which purpose.


Collect logs:

Logs are one of the most important sources of information for troubleshooting.

Generate a Log Snapshot from the GUI:

Depending on the FortiNAC version, use one of the following methods.

  • Log Snapshots Page:

From the FortiNAC web interface:

  1. Go to System > Settings > Logs > Log Snapshots.

  2. Select Create Log Snapshot.

  3. Select the time range that covers when the issue occurred.

  4. Download the generated .tar.gz file.

  • Help Menu:

In current FortiNAC-F versions:

  1. Open the Help menu in the upper-right corner.

  2. Select Download Logs.

  3. Follow the on-screen options to collect and download the log package.

The GUI location may vary depending on the FortiNAC version.

Generate a Log Snapshot from the CLI:

Or from the CLI, run the following command:

execute log-snapshot create


The FortiNAC-F CLI, run the following command:

execute enter-shell

sudo grab-log-snapshot


The snapshot is saved to:

/bsc/campusMgrUpdates/log-snapshot-*.tar.gz


Upload large files to the case:

If the log snapshot is too large to attach directly, upload it via SFTP. See KB 414380 for step-by-step instructions:

execute enter-shell

sftp -P 2222 <USER_ID>@<FTP_Address>:/ <<< $'put /bsc/campusMgrUpdates/log-snapshot-*.tar.gz'


Key file locations:

  • Log snapshots:

/bsc/campusMgrUpdates/log-snapshot-*.tar.gz


  • Packet captures:

/bsc/campusMgrUpdates/capture*.pcap


  • Database backups:

/bsc/backups/database/FortiNAC_DataBase_BackUp_*.gz


Enable Real-Time Debug Logging:

For issues that can be reproduced live, enable debug plugins to capture detailed output.

diagnose debug plugin list

diagnose debug plugin enable RadiusManager

diagnose debug plugin tail RadiusManager

diagnose debug plugin disable RadiusManager


Common debug plugins include:

MasterLoader, RadiusProxy, PersistentAgent, Nessus, Datasyncer.

Make sure to disable debug logging after the required information has been collected.

See Technical Tip: FortiNAC general troubleshooting guide for the complete procedure.

Capture network traffic:

Packet captures are essential for authentication, RADIUS, and connectivity issues.

Run the following command:

execute tcpdump -i any host <IP_ADDRESS> -w capture.pcap


To transfer the file to another server, enter the shell:

execute enter-shell

scp /home/admin/capture.pcap user@<server_IP>:/path/


See Technical Tip: Run tcpdump in FortiNAC-F and save capture as a file for the complete procedure.


Save the Configuration:

execute backup database

show full-configuration


Database backups are stored in the following location:

/bsc/backups/database/FortiNAC_DataBase_BackUp_*.gz


See Technical Tip: How to export DataBase backup from FortiNAC-F for the complete procedure.

Share a Network Diagram:

A simple diagram showing the following helps understand the setup quickly:

  • FortiNAC appliance(s) with IP addresses and interfaces.

  • Connected switches, routers, and wireless controllers.

  • RADIUS clients.

  • Isolation and registration of VLAN assignments.

  • DHCP server placement.

Even a hand-drawn sketch with IPs and VLANs labeled is helpful.

Provide a Timeline:

A clear timeline correlating actions with timestamps makes it easier to pinpoint the issue in the logs.

Example:

  • 10:05:00 EST: Laptop connected to SSID 'Corporate'.

  • 10:05:02 EST: RADIUS Access-Request sent to FortiNAC.

  • 10:05:05 EST: FortiNAC responded with Access-Accept, VLAN 100.

  • 10:05:10 EST: Browser showed 'No Internet', expected the registration portal.

Checklist Before Submitting a Case:

  • Checked the FortiNAC Knowledge Base and official documentation.

  • Confirmed the support contract is active for all affected products.

  • Verified the firmware version is within the Product Life Cycle.

  • Confirmed the issue is not a Professional Services, migration, or NFR request.

  • Clear description of expected versus actual behavior.

  • FortiNAC version, model, deployment type, and hypervisor.

  • Date, time, and timezone when the issue started.

  • Log snapshot covering the incident window.

  • Packet capture (if applicable).

  • Network topology diagram.

  • List of recent changes.

  • Reproduction steps and timeline.

  • One issue per case, separate cases for separate problems.

Providing this information when the case is opened helps TAC begin the investigation immediately and may reduce the time required to identify and resolve the issue.

Related Information:

For Similar information, refer to the following article:
Technical Tip: How to enhance support experience with TAC engineer

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!