Description | This article describes how to configure the Huawei switch RADIUS attribute NAS-Port-Id to be recognized by FortiNAC. |
Scope | FortiNAC |
Solution |
By default, the Huawei switch sends the Radius Attribute NAS-Port-Id in the below format, which is not recognized by FortiNAC:
NAS-Port-Id = [slot=0;subslot=0;port=6;vlanid=69;interfaceName=GigabitEthernet0/0/6] (RadAttr Type=string) (FNAC doesn't correctly map the device to the interface.)
The Huawei switch config should look like this:
radius-server template rd1
In specific cases like the model S5731 or other similar models, two other commands need to be added in the switch config:
radius-server attribute translate
This is due to the fact that this model will send another RADIUS attribute during authentication: [NAS-Port = [177128] (RadAttr Type=integer)] that does not contain any valid information to be used by FortiNAC. This will result in the policy being applied in the wrong location. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.