Skip to main content
saori
New Member
February 15, 2026
Question

Fortinac Network Authentication times

  • February 15, 2026
  • 3 replies
  • 175 views

Hello! I wanted to ask for people who are using fortinac for authentication with radius and mac traps alongside persistent agent. How long does it take for a user to go from isolation vlan to production?

3 replies

Stephen_G
Moderator
Moderator
February 19, 2026

Hello saori,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

If anybody else has any info or advice, please feel free to contribute!

Regards,
Stephen_G - Fortinet Community Team
Stephen_G
Moderator
Moderator
February 19, 2026

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP. If anyone else has any ideas in the meantime, please feel free to contribute!

Stephen_G - Fortinet Community Team
Hatibi
Staff & Editor
Staff & Editor
February 19, 2026

With RADIUS the VLAN change should be happening in a matter of seconds.

When the host is registered, online and matches a network access policy, FortiNAC will send a Disconnect Message or CoA that triggers a new authentication request. FortiNAC then sends the Accept-Accept with new VLAN access value and any other attributes configured.

 

If you have a delay in this scenario you need to check with tcpdump if FortiNAC sends the DM immediately after policy match and if the Switch/WLC responds with DM ACK to clear the current radius session and trigger the new auth request. A packet capture will help you identify where the problem resides.