Skip to main content
Hatibi
Staff & Editor
Staff & Editor
November 4, 2024

Troubleshooting Tip: Troubleshoot Security Fabric Instability between FortiGate and FortiNAC

  • November 4, 2024
  • 0 replies
  • 1036 views
Description This article describes how to troubleshoot the Security Fabric integration between FortiNAC and FortiGate. 
Scope FortiGate, FortiNAC-F.
Solution

The Security Fabric integration with FortiNAC is used for intent-based segmentation. FortiGate uses Dynamic firewall address objects in its Firewall policies to control access. FortiNAC uses REST API to dynamically update these objects through logon/logoff event triggers each time it detects host posture changes: Security Fabric Configuration with FortiNAC

 

The first step, to identify if there are any Security Fabric issues, is the 'System Events' log section in FortiGate GUI. Go to Log & Report -> System Events -> Logs and in the 'Log Description' filter, enter the following log events:

  • Device joined the Security Fabric.
  • Device left the Security Fabric.

 

Figure 1. Detect Fabric Instabilites through FortiGate System event logs.Figure 1. Detect Fabric Instabilites through FortiGate System event logs.

 

This will help in defining if there is a pattern in the occurrence of the device joining/leaving the fabric integration.

To investigate further, enable the following debugs:

 

FortiGate debugs:

 

diagnose debug reset
diagnose debug console timestamp enable
diagnose debug application csf -1
diagnose debug application httpsd -1
diagnose debug application nodejs -1
diagnose debug application authd -1
diagnose debug enable

 

FortiNAC debugs:

 

  1. FortiNAC (CentOS).

 

logs

nacdebug -name BridgeManager true
nacdebug -name DeviceInterface true
nacdebug -name SSOManager true
nacdebug -name SecurityFabricManager true
tf output.master

 

  1. FortiNAC-F (NACOS).

 

diagnose debug plugin enable BridgeManager
diagnose debug plugin enable DeviceInterface
diagnose debug plugin enable SSOManager
diagnose debug plugin enable SecurityFabricManager

diagnose tail -F output.master

 

Filtered FortiGate CLI output will show the following events:

 

2024-10-28 17:37:28 <XXXX-U> 02 __ssl_recv()-538: illegal packet received from <FORTINAC_IP_ADDRESS>:33272 received:4111 len:4334
2024-10-28 17:37:28 <XXXX-U> 10 daemon_send_internal_msg_ex()-211: Sending internal msg NSTD_INTERNAL_MSG_DISCONNECT_FGT data_len=4
2024-10-28 17:37:28 <XXXX-U> 10000000 __fgt_destruct()-258: closing downstream <FORTINAC_IP_ADDRESS>:33272
2024-10-28 17:37:28 <XXXX-U> 04 conn_free_fgt_info()-197:
2024-10-28 17:37:28 <XXXX-U> 10000000 conn_free_fgt_info()-201: Freeing fgt FNVMXXXXXXXXXX reason=2 
2024-10-28 17:37:28 <XXXX-U> 40000 sync_unpriv_generic_connection_event()-358:
2024-10-28 17:37:28 <XXXX-U> 04 nstd_chan_data_ep_hd()-194:
2024-10-28 17:37:28 <YYYY-M> 04 nstd_chan_data_ep_hd()-194:
2024-10-28 17:37:28 <YYYY-M> 04 nstd_chan_data_ep_hd()-194:
2024-10-28 17:37:28 <YYYY-M> 10 daemon_chan_data_cb()-73: Received internal msg NSTD_INTERNAL_MSG_DISCONNECT_FGT data_len=4
2024-10-28 17:37:28 <YYYY-M> 10000000 __fgt_destruct()-243: <FORTINAC_IP_ADDRESS>:33272 destruction requested by the other process
2024-10-28 17:37:28 <YYYY-M> 10000000 __fgt_destruct()-258: closing downstream <FORTINAC_IP_ADDRESS>:33272
2024-10-28 17:37:28 <YYYY-M> 04 conn_free_fgt_info()-197:

 

FortiNAC will send SSO information for the IP range objects specified in the 'SSO Addresses' and 'VPN addresses' in the FortiGate model configuration. If all objects are selected, FortiGate will report sizing issues when it receives the information from FortiNAC. See this document Addresses

 

It is recommended to apply only the subnets or IP ranges where control through dynamic address objects is planned. If all subnets are selected, FortiGate will receive unnecessary information and update objects that will never be used in Firewall policies. Additionally, this will case Fabric instability issues as in the above example.

 

This is a known issue (ID 1140987), which has been resolved in FortiNAC v7.4.2 and v7.6.3.

 

Related documents:

Fortinet Security Fabric/FSSO Integration

FortiNAC tag dynamic address

Allow FortiNAC to join the Security Fabric

Technical Tip: Configure Security Fabric with FortiNAC & FortiGate

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!