Question
FortiNAC, AD user cannot override itself if created by RADIUS
HI FNAC admins
FortiNAC-F 7.2.9.
I have this scenario:
- A new AD users (not added to FNAC yet) connects to SSID managed by FNAC from a client having NAC agent
- FNAC adds it automatically to user DB (created from RADIUS connection) , and it adds it not as “Loaded from Directory”, but just like local user, and remains the same even after AD sync
- As it didn’t add it as “Loaded from Directory” it doesn’t match my UHP neither my access policy, so it is dropped in isolation
- So I have to remove the user manually and let it created by LDAP automatically after sometime
My question:
- Is there a way to force AD user override existing user created from RADIUS connection
- Otherwise is there a way just to preload all ad users to FNAC user DB even before any user connects
- Or any other flexible/automatic solution
