Troubleshooting Tip: Unable to move a client between NAC-Enabled ports on FortiSwitch
| Description | This article describes an issue where a client cannot move between NAC-enabled ports due to the match-type override setting. |
| Scope | FortiSwitch and FortiGate v7.4, v7.6 in FortiLink mode. |
| Solution | Reason: See FortiSwitch port flap with laptop connected with wifi/wired using FortiClient EMS tags.
Configuration example:
Temporary workaround:
The issue can be temporarily resolved by manually clearing the NAC policy match entry:
execute switch-controller switch-action mac-device-reset nac <MAC-address>
Solution:
In FortiGate OS v7.6.3, a new option has been introduced:
Behavior of match-remove:
Note: If the device remains connected (link stays up), the entry persists until the match-period expires or indefinitely if configured.
Configuration example:
|
