FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
scitlak
Staff
Staff
Article Id 365587
Description This article describes how to change Default Enforcement on an SSID by using CLI.
Scope FortiNAC, FortiNAC-F.
Solution

FortiNAC does not allow to change Default Enforcement as 'deny' or 'bypass' by using GUI. However, it can changed by using CLI.

19.12.2024_10.51.31_REC.png
First, the SSID's DBID should be learned by using the 'dumpports' command shown below. 

19.12.2024_10.55.08_REC.png

 

After learning the DBID of the SSID, Default Enforcement can be changed by using the command below. The following command that will assign a value as '0' will change the enforcement to 'Deny'. The value '1' represents 'Bypass' and '2' represents 'Enforce'.

device -dbid <SSID_DBID> -setAttr -name DefaultAction - value 0


19.12.2024_10.52.36_REC.png

Note: The above change will not reflect on the GUI, and the GUI will display Default Enforcement's value as 'Enforce'. However, when a host tries to authenticate by using the SSID and if it does not match any Network Access Policy, FortiNAC rejects the authentication request since Default Enforcement is denied. In this case in Radius logs, a log like the one below should be displayed.
 

Tue Dec 17 17:18:16 2024 : Auth: (1078) Rejected in post-auth: [6C-88-14-A1-D7-D0] (from client 192.168.0.254 port 0 cli 6C-88-14-A1-D7-D0)
Tue Dec 17 17:18:16 2024 : Auth: (1078) Login incorrect (Default Access Deny (Post-Auth) [6C-88-14-A1-D7-D0] (from client 192.168.0.254 port 0 cli 6C-88-14-A1-D7-D0)
Tue Dec 17 17:18:16 2024 : Debug: (1078) Delaying response for 1.000000 seconds
Tue Dec 17 17:18:16 2024 : Debug: Waking up in 0.3 seconds.
Tue Dec 17 17:18:16 2024 : Debug: Waking up in 0.6 seconds.
Tue Dec 17 17:18:17 2024 : Debug: (1078) Sending delayed response
Tue Dec 17 17:18:17 2024 : Debug: (1078) Sent Access-Reject Id 6 from 192.168.0.202:1812 to 192.168.0.254:15902 length 71
Tue Dec 17 17:18:17 2024 : Debug: (1078) Reply-Message = "Default Access Deny (Post-Auth)"