Skip to main content
HS08
Explorer
July 10, 2026
Question

Forinac sometime not send CoA

  • July 10, 2026
  • 9 replies
  • 128 views

If the endpoint was idle for some time then when i change the group on the NAC, I can see the fortinac not send the CoA to the switch.

We can see here the last fnac send the CoA is 14:02:18 then i change the group for that host at 14:30 and there is no CoA bsend to the switch

 

 

9 replies

ebilcari
Staff
Staff
July 10, 2026

The host must be online in FNAC and during policy evaluation, be detected as connected to the wrong network for the CoA/DM to be sent.

Emirjon
HS08
HS08Author
Explorer
July 10, 2026

yes the host is online, the client can ping to the fnac also from fnac can send message to the host. But when i change the group then there is no CoA. Any other thing should be checked? Also we no need to have PA for changing the vlan right?

ebilcari
Staff
Staff
July 10, 2026

Actually, FNAC needs to see the host as connected/online through the network device to which the host is connected, direct communication with the host itself is not required.
Once the CoA/DM is sent, the port is typically bounced (disabled and re-enabled), and the IP address is renewed. PA Optimization when enforced through the agent, can help accelerate the IP renewal process but an agent is not required for FNAC to change the hosts network assignment.

Emirjon
ebilcari
Staff
Staff
July 16, 2026

This appear to be a custom attribute added in the ‘Access-Accept’ and is not a dedicated CoA/DM message. Check in the model configuration the attributes that are configured (hover mouse). By default FNAC will try to merge the attributes from the default group and additional ones. 

 

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.