Description
This article describes how to configure and troubleshoot Firewall TAGs with FortiGate and FortiNAC.
Related documents:
Scope
FortiGate and FortiNAC Legacy.
Solution
device -ip <IPaddress> -setAttr -name ForceSSO -value true
nacdebug -name DeviceInterface true
nacdebug -name SSOManager true
Device -ip <IPaddress> -setAttr -name DEBUG -value "ForwardingInterface TelnetServer"
grab-log-snapshot
The script will collect and zip a large number of files.
This will take several minutes.
The resulting zip file (log-snapshot-<hostname>-<timestamp>.tar.gz) is located in /tmp directory.
See Technical Tip: How to get a debug log report from FortiNAC.
nacdebug -name DeviceInterface false
nacdebug -name SSOManager false
Device -ip <IPaddress> -delAttr -name DEBUG -value "ForwardingInterface TelnetServer"
Verify which debugs are enabled:
nacdebug -all | grep -i true
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.