Skip to main content
HS08
Explorer
August 5, 2026
Solved

Fnac Radius and Mac Trap

  • August 5, 2026
  • 11 replies
  • 51 views

My port switch config is

interface GigabitEthernet1/0/1
switchport access vlan 100
switchport mode access
switchport voice vlan 200
authentication order dot1x mab
authentication port-control auto
authentication periodic
mab
snmp trap mac-notification change added
snmp trap mac-notification change removed

dot1x pae authenticator
spanning-tree portfast
end
 

I think i no need to add two bold command above since the radius will be used and not snmp. Am i right?

 

Best answer by AEK

I confirm. Either use RADIUS or SNMP traps, but not both.

11 replies

AEK
SuperUser
AEKAnswer
SuperUser
August 5, 2026

I confirm. Either use RADIUS or SNMP traps, but not both.

AEK
ebilcari
Staff
Staff
August 5, 2026

This guide is specific to FortiSwitch, but the same should apply for all managed network devices:
Note: If Syslog or RADIUS is or will be configured, skip this section. Do not configure L2 MAC traps on ports configured for RADIUS authentication.

https://docs.fortinet.com/document/fortinac-f/7.6.0/fortiswitch-standalone-integration/836898/5-snmp-mac-notification-traps-optional

Emirjon
HS08
HS08Author
Explorer
August 5, 2026

hi ​@AEK  ​@ebilcari 

If both is enabled then which one will be used? Also is there any negative impact if both enabled?

ebilcari
Staff
Staff
August 5, 2026

A race condition can occur in FNAC during host evaluation because the two types of notifications may reach FNAC at different times. This behavior has also a negative impact on performance as FNAC must perform unnecessary processing by evaluating the same host more than once.

Emirjon
HS08
HS08Author
Explorer
August 5, 2026

Thanks ​@ebilcari 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.