Skip to main content
HS08
Contributor III
July 22, 2026
Solved

Fortinac Link Status

  • July 22, 2026
  • 13 replies
  • 105 views

Why link status for each port is different between the device and fortinac? 

On the device port g1/0/27 - 31 is up but in the NAC is different

 

Best answer by ebilcari

@HS08 Yes, basically this command changes the way the MAC address table is read.

Default is set to:

ATTRIBUTE_NAME=MacAddressTableDynamic
{
GROUP=MacAddressTable
ATTRIBUTE=MacAddressTableDynamic
WRITE=show mac address-table | exclude STATIC|static
RETVAL=#
}

 

13 replies

ebilcari
Staff
Staff
July 22, 2026

Host and port status are usually updated through SNMP traps, RADIUS authentication, or an L2 poll. Does the behavior remain the same after running a manual L2 poll on this switch?

Another possibility is that the port is operationally up, but no valid MAC address is being learned on the port. In that case, FNAC may not be able to associate the host with the port and update its status accordingly.
So, do a quick check of the switch MAC address table to verify whether the hosts MAC address is being learned on the expected port.

Emirjon
HS08
HS08Author
Contributor III
July 22, 2026

Hi ​@ebilcari 

Based on below picture we can see  there are valid mac address on interface g1/0/29 but in fortinac this interface is ‘Not Connected’. Try to poll the device manually but still same.

 

 

ebilcari
Staff
Staff
July 22, 2026

If the port and host status are not updated after a successful L2 poll, this may indicate an issue with the switch integration in FNAC.
Was this switch automatically mapped by FNAC or did you have to manually select a similar model from the device mapping list?
You can also try running a ‘Resync Interface’ or check the output of ‘Test Device Mapping’ to verify the connected hosts that can be read from the switch.

Emirjon
Staff & Editor
July 30, 2026

Hello HS08,

By default, static MAC Addresses are ignored by FortiNAC.
After RADIUS auth (Dot1x or MAB auth) the switch marks the authenticated device mac address as static entries in the mac address table (Expected behavior by switches). To resolve the L2 poll behavior you need to follow the article ebilcari has mentioned.

HS08
HS08Author
Contributor III
August 2, 2026

if by default the mac address will be change to static if the port controlled by nac then why fortinac also not poll the static mac as default?

ebilcari
Staff
Staff
August 4, 2026

As I remember, on Cisco switches this was applied only on ports that had Port Security enabled. It now make sense for FNAC to automatically enable this option when RADIUS is configured for the switch.

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!