FortiNAC-F
FortiNAC-F is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks. For legacy FortiNAC articles prior to FortiNAC-F 7.2, see FortiNAC.
shahzeb
Staff
Staff
Article Id 418065
Description This article describes the solution to the problem where adapter's location of connected hosts changes between active and passive WLC.
Scope FortiNAC-F.
Solution

When Huawei controllers are running in HA, the connected user's location keeps changing between active and passive controller, affecting Location based policies.


For example, the following two screenshots show a user connected to both active and passive controllers at two different points in time:

 

2025-08-20 12_04_07-GoTo Meeting.png

 

2025-08-20 11_58_16-.png

 

Troubleshooting:

 

It was observed, even though the secondary controller isn't an active wireless controller, connected device records and MAC addresses are synced between them.
Therefore, whenever FortiNAC does L2 Poll, both of them responds with the MAC address table and whichever is polled later gets the adapter association in the FortiNAC.

 

2025-08-20 12_16_22-.png

 

2025-08-20 12_15_46-.png

 

Solution:

  • L2 poll should only be kept enabled on Primary WLC.
  • If adapter's location is called in the Users and Host profiles, both Primary and Secondary WLC reference should be called.
Contributors