Skip to main content
Akmostafa
Explorer
April 30, 2024
Solved

FortiNAC not responding to PA connections

  • April 30, 2024
  • 7 replies
  • 3840 views

Hi Team,

 

I have installed persistence agent on a client computer, and edited the windows registry to specify the server IP 10.0.200.247 (port1 interface of FortiNAC)

Noted from capturing packets along the path, that the agent tries to imitate the tcp connection to 10.0.200.247 but no reply is coming back to any syn packet.
attached also the TCP dump from the FortiNAC (attached testfile.pcap) showing syn packets from 172.16.14.27 to 10.0.200.247 but no syn-ack seen, also trying to telnet port 4568 fails from the client machine.

The default route on FortNAC on port 1 is 10.0.200.1 (Fortigate) and from the same client machine I can access FortiNAC on its port1 ip for management on port 8443 and SSH . (but not port 4568)

 

Tried to restart the service many times on both the client machine and the FortiNAC.

 

Note, it is layer 3 deployement and the host is not in an isolation network.

Also note that it is not an SSL or certificate related issue, because the TCP connection is failing to be established, I am not reaching the TLS negotiation phase.

Best answer by ebilcari

Since you are running the new FNAC-F a common mistake is forgetting to allow the service on port configuration:
config system interface
  edit port1
   set allowaccess dhcp dns http-adminui https-adminui nac-agent ping radius-local snmp ssh syslog

 

The added confusion happens because the packet capture in FNAC is still able to receive the packets but without this command the service will not listen on that interface. Some common recommendations can be also found in this article.

7 replies

AEK
SuperUser
SuperUser
April 30, 2024

Hi Mostafa

Have you installed a certificate (trusted by clients) on FNAC for agent communication?

If not then there will be no communication between them.

AEK
Akmostafa
AkmostafaAuthor
Explorer
April 30, 2024

HI AEK, I agree, and already done this step.

Again please note that the TCP 3-way hand shake is not successful.

 

If it is a certificate issue, I would see in packet capture that TCP connection is done and then a failure in TLS negotiation, but this is not the case in my situation.

 

Anyways, I have done this step, and imported the CA that signed the PA certificate to be trusted in the client machine.

AEK
SuperUser
SuperUser
April 30, 2024

Is the port listening?

Try with telnet from your FortiGate then from the client as well.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!