FortiNAC-F
FortiNAC-F is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks. For legacy FortiNAC articles prior to FortiNAC-F 7.2, see FortiNAC.
scitlak
Staff
Staff
Article Id 348849
Description This article describes how to configure FortiNAC to proxy MAB Requests to Radius Server.
Scope FortiNAC -F 7.4, FortiNAC -F 7.6.
Solution

Before FortiNAC -F version 7.4 and version 7.6, MAB requests proceeded and were answered by FortiNAC -F locally, and it was not possible to proxy it. FortiNAC -F version 7.4 and version 7.6 now allow proxying. Follow the steps below to configure it:

 

  1. Under 'Service Connectors', create a RADIUS server.

    11.10.2024_17.20.32_REC.png

     

  2. Create a new 'Virtual Server' under Network -> RADIUS and select the RADIUS server that has been created under 'Service Connectors`.

    11.10.2024_17.21.59_REC.png

     

  3. Under Device Model Configuration, set the 'Server Configuration' as a Virtual Server configuration that contains a RADIUS Proxy configuration. As shown below: with FortiNAC -F 7.6, there are no more options for RADIUS Proxy or RADIUS Local. These options are still available in version 7.4 and, in this case, the RADIUS mode should be set to Local.

    11.10.2024_17.24.11_REC.png

     

  4. In the NAS client, RADIUS authentication should be set to the port number that has been configured under Network -> RADIUS -> Configuration. The 'Proxy MAB Requests" option should be selected under Network -> RADIUS -> Configuration.

    11.10.2024_17.29.36_REC.png

     

  5. When an MAB authentication request is initiated from NAS, FortiNAC will proxy it to the RADIUS server as shown below.

    11.10.2024_15.45.23_REC.png

     11.10.2024_15.45.44_REC.png

     

    11.10.2024_15.45.59_REC.png

     

    11.10.2024_15.46.11_REC.png