FortiNAC is a s a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.

This article describes a behavior where user attribute information is no longer accurate after adding and removing LDAP directory models. Some user records can still be associated to the old directory.

This prevents information from updating properly when a directory synchronization is run.


Symptoms include hosts not matching policies based on LDAP group membership.


For instructions to replace a directory, refer to the following link: 

Scope Version: 8.8 and greater.

1) Perform database backup.

2) Modify the new LDAP directory model and change the name to the old directory name.

3) Select OK (This re-writes the name attribute to all of the user records and can take a few minutes).

4) Change the LDAP directory name back to the new name and select OK.