| Description | This article describes a known issue with WPA2-Enterprise tunnel SSIDs using RADIUS authentication, where Wi-Fi client group assignments are not retained after roaming to a different FortiAP. |
| Scope |
FortiGate 7.4, v7.6.3 and earlier. |
| Solution |
When a user roams to a different AP using WPA2-Enterprise with RADIUS authentication, most of the groups assigned to the user are not retained. Only one group remains, which may lead to incorrect access control depending on the firewall policy configuration.
diagnose firewall auth list
Workaround:
Resolution: This issue has been resolved in:
These timelines for firmware release are estimated and may be subject to change. Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.