Description |
This article describes how to change a 'radius disconnect message' to a 'bounce-port' VSA radius attribute in radius-accept messages. |
Scope | FortiNAC-F v7.2.X |
Solution |
V7.2.X contains a global option that can change the message from a disconnect to a CoA, but attributes are not user-configurable (no option to configure additional RFC5176 Radius attributes).
The global option will instruct the code to create a system-defined CoA request. To configure the global option, execute these commands in the CLI of FortiNAC-F:
execute enter-shell globaloptiontool -name radiusServer.use.coa.for.disconnect -set true
PCAP file before applying the global option:
output.master debugs:
attributes = 1f 13 63 63 2d 39 36 2d 65 35 2d 64 36 2d 36 63 2d 33 37
After applying the global option:
PCAP radius packet details:
RADIUS Protocol |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.