Skip to main content
Rabeb_Ali
Explorer II
December 24, 2025
Question

How to handle MAB locally in FortiNAC ?

  • December 24, 2025
  • 6 replies
  • 697 views

Hello Community,

When FortiNAC is in proxy mode, the PC authenticates successfully but the IP phone MAB requests are always forwarded to Radius Server and rejected.

I  tried to create an authentication policy to override this behavior and force local MAB authentication on FortiNAC, but it did not work.

Is it possible to handle MAB locally while FortiNAC is running in proxy mode?

6 replies

AEK
SuperUser
SuperUser
December 24, 2025

Ha Rabeb

If I remember well I was used to configure on FNAC both RADIUS proxy and local RADIUS at the same time. Only thing needed is to change the listening port of one of them, e.g.: use legacy port 1645 for local RADIUS.

AEK
ebilcari
Staff
Staff
December 24, 2025

Check if this setup has the option 'Proxy MAB Requests' enabled like shown below:

 

proxymab.PNG

 

By default, this option is disabled. Authentication policies are not related to RADIUS authentication requests originating from NAS devices.

Emirjon
Rabeb_Ali
Rabeb_AliAuthor
Explorer II
December 24, 2025

thank you for your replies, the proxy MAB Requests is enabled and the RADIUS server is configured to listen on port 1645, but MAB requests from IP phones are still not handled locally by FortiNAC and continue to be forwarded to NPS and rejected

AEK
SuperUser
SuperUser
December 24, 2025

It means you shouldn't proxy the MAB requests, but treat them locally.

AEK
Rabeb_Ali
Rabeb_AliAuthor
Explorer II
December 24, 2025

Exactly, that is my issue. I want FortiNAC to process MAB requests locally and not proxy them

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!