Skip to main content
Khurramtariq
Explorer
December 13, 2024
Solved

FortiNAC 802.1X Authentication VLAN change/unauthenticated

  • December 13, 2024
  • 10 replies
  • 4419 views

Dear All

We have deployed FortiNAC 7.6 latest version and using it for 802.1X authentication using Cisco switches and AD authentication through WinBind, authentication was working well for some customers but its not stable , now we are facing that cisco showing authentication successful but on FortiNAC its showing "unauthenticated" and remain in Isolation/authentication VLAN means VLAN change is not happening , this product is strange sometimes becomes very slow. We are using Peap MSCHAPv2 with user authentication

please suggest

Best answer by ebilcari

There is a common misconception regarding the Authentication policy and status of the host (red A). This authentication can be treated as a second layer of authentication through the portal or Persistent Agent which is not required when the host is already authenticating with RADIUS. If this is the case make sure to not enforce Authentication because is not required.

10 replies

ebilcari
Staff
ebilcariAnswer
Staff
December 13, 2024

There is a common misconception regarding the Authentication policy and status of the host (red A). This authentication can be treated as a second layer of authentication through the portal or Persistent Agent which is not required when the host is already authenticating with RADIUS. If this is the case make sure to not enforce Authentication because is not required.

Emirjon
Khurramtariq
Explorer
December 15, 2024

HI Ebilcari

Thanks for your contribution , i unchecked "forced authentication" from switch port on FortiNAC>Inventory>switch port, now 2-3 PC are authenticating successfully and getting IP addresses too in test run case, we are monitoring the behavior and then will update. I cannot share screenshot here but on FortiNAC its still showing unauthenticated host "A" in red showing , also IP address of one host is showing in adapter options and other host is not showing , both are on same network, same authentication and windows

ebilcari
Staff
Staff
December 16, 2024

The host status (need authentication) should change next time the host connects in the network and the port doesn't have the authentication enforced.

The IP address of the hosts usually is learned through the L3 device that is the gateway of the hosts and have that information in its ARP table.

Emirjon
AEK
SuperUser
SuperUser
December 13, 2024

Hi Tariq

If Cisco switch said it is authenticated then the RADIUS response was ok. Try confirm in RADIUS debug logs if the response was positive and if RADIUS has sent the right destination VLAN to the switch in the response.

Also what do you exactly mean by it works well for some customers but is not stable? If you mean it is intermittent then one of the possibilities is a network issue, I mean you may try to check with sniffer (tcpdump on NAC) if the RADIUS queries are always reaching the NAC server and the responses are reaching the switch.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!