FortiNAC-F
FortiNAC-F is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks. For legacy FortiNAC articles prior to FortiNAC-F 7.2, see FortiNAC.
scitlak
Staff
Staff
Article Id 395882
Description This article describes how to troubleshoot and fix the "No Winbind Domain Match" issue that can occur when Multiple Domains are in use.
Scope FortiNAC, FortiNAC -F.
Solution This issue can occur when Multiple Domains are in use in the FortiNAC Winbind configuration and when the NetBIOS names are configured with lowercase.

11.06.2025_15.27.14_REC.png

In this case, FortiNAC Radius service generates the following logs while the Radius request has the correct Domain realm.

 

Login incorrect (No Winbind Domain Match): [TEST\admin] (from client 10.191.20.203 port 0)

 
To fix the issue, the NetBIOS name should be configured with uppercase as shown below.

11.06.2025_15.33.19_REC.png

 

When the NetBIOS name is configured as uppercase, FortiNAC can parse the Domain realm and authenticate it against the correct Winbind Domain.

 

Login OK: [TEST\admin] (from client 10.191.20.203 port 0)


Related article:

Technical Tip: MSCHAPv2 authentication, join FortiNAC in domain and checks