Skip to main content
AEK
SuperUser
SuperUser
August 26, 2025
Solved

FortiNAC and WLC without CoA

  • August 26, 2025
  • 7 replies
  • 1145 views

Hi FNAC Admis

  • FortiNAC-F 7.2.9
  • Ruckus ZD1200 v10.x

The WLC doesn't support CoA. So if I understand well the FNAC will send a RADIUS disconnect request in order to change the client's VLAN. But this doesn't happen.

The test I've made is to fail the scan of the client. When the client is in wire network it is sent to quarantine, however when it is on WiFi it is not sent to quarantine and not even disconnected.

Furthermore when the host is at risk and I try disconnect and reconnect to the SSID, it is put in the production VLAN instead of the isolation VLAN.

Followed FortiNAC's "Ruckus Zone Director Wireless Controller Integration" document, but it doesn't mention anything about the issue and its resolution.

Best answer by ebilcari

In this integration (Ruckus), FNAC is expecting the support for CoA/DM to disconnect the hosts. Does this WLC support CoA/DM, or is it rejecting the requests due to a possible misconfiguration?
To facilitate troubleshooting you can also try to manually send a CoA/DM with the following command:
> sendcoa -ip x.x.x.x -mac YY:YY:YY:YY:YY:YY -dis
* replace x.x.x.x with the IP of the WLC and YY:YY.. with the MAC address of the end host (host should be connected when this command is sent).

 

If this WLC does not support any form of CoA/DM, the integration will be limited in functionality.

7 replies

ebilcari
Staff
ebilcariAnswer
Staff
August 27, 2025

In this integration (Ruckus), FNAC is expecting the support for CoA/DM to disconnect the hosts. Does this WLC support CoA/DM, or is it rejecting the requests due to a possible misconfiguration?
To facilitate troubleshooting you can also try to manually send a CoA/DM with the following command:
> sendcoa -ip x.x.x.x -mac YY:YY:YY:YY:YY:YY -dis
* replace x.x.x.x with the IP of the WLC and YY:YY.. with the MAC address of the end host (host should be connected when this command is sent).

 

If this WLC does not support any form of CoA/DM, the integration will be limited in functionality.

Emirjon
AEK
SuperUser
AEKAuthor
SuperUser
August 27, 2025

Thanks for your feedback, Emirjon.

This WLC doesn't support CoA but it should support DM as per my research.

So is there something additional to configure in FortiNAC to force it use DM instead of CoA? Or does FNAC use DM automatically when the WLC doesn't support CoA?

AEK
ebilcari
Staff
Staff
August 27, 2025

Actually FNAC (7.2) will send DM messages, this apply also for the manual command (sendcoa). As long as the WLC supports DM and the relevant attributes are correctly parsed during authentication, it should function as expected. Full support for standard CoA was introduced in branch 7.6.

Emirjon
AEK
SuperUser
AEKAuthor
SuperUser
August 28, 2025

Hi Emirjon

 

After troubleshooting I found that the DM is supported on my WLC Ruckus ZD1200, and it actually works.

So for example when I change the target network in the policy, it actually changes the VLAN for the affected host but only once L2 polling is done, never instantly. And I can see with tcpdump that the DM message is sent to the WLC just after L2 poll is done.

 

As far as I remember in my old integration the VLAN changes instantly for WiFi users, but it seems with my ZD1200 it is done on L2 poll.

Any idea why this behavior?

 

PS:

  • I'm using RADIUS proxy here (if the info is relevant)
  • On my L2 switches the VLAN switching is working just perfect (no RADIUS here)
AEK
ebilcari
Staff
Staff
August 28, 2025

Good to hear that the DM configurations have been sorted out. Policy evaluation is triggered when a host status changes (e.g. Rogue, At-risk) or when a network event is received (such as SNMP traps, new authentications, syslog messages, or L2 polling). This is expected behavior. Making configuration changes in UHP or NAP does not trigger a policy evaluation for the hosts that are expected to match.

To simulate a real scenario, you can register a rogue host or verify compliance using agent scanning.

Emirjon
AEK
SuperUser
AEKAuthor
SuperUser
August 28, 2025

You are right. It works fine when disabling host.

Thanks again Emirjon!

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!