NAC Policy devices clearing out multiple times per day
Hello all. Looking for anybody who has run into this issue and may be able to provide guidance.
We have a pair of FGT 70Gs running 7.4.9 connected to a stack of 148F FSWs running 7.2.5. This is our standard stack and we run it at dozens of sites.
We have NAC enabled via the built in managed FSW setting (not FortiNAC). We add devices via NAC policies individually and via wildcard filters such as Vendor name and device type (Example: IP Phone). Our switchports are configured in NAC mode and based on the device that plugs in, the dynamic VLAN will assign to what's configured in the NAC policy.
Anywhere from a couple to a few times a day, users with devices plugged into these NAC-mode switchports say their devices are doing network hard down, and then coming back up moments to minutes later. I checked logs and am seeing that the entire NAC MAC address cache appears to be deleted out and then added back, all at once but separated by short periods of time. This aligns exactly with when the issue was reported/experienced. Please see attached logs and configurations for reference.
Logs:


 
 NAC Config:
I did also see this tip out there that may be related: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Resolving-port-flapping-issues-when/ta-p/367000

 I haven't yet been able to determine why the NAC devices are being cleared out and re-added but it appears that the above fix couple help keep them while the root cause happens (STP event, flapping ports, etc?).
Any help is appreciated!
