Description
Scope
Version: 8.x and greater
Solution
1) Review the affected VPN client’s entry in the database (ProbeObject) to determine what information is missing. Login to the appliance CLI as root and type
RemoteAccess -remoteIP <client VPN IP>
Example:
RemoteAccess –remoteIP 172.16.196.10
If no results are returned, the proper syslog information was either not received or not processed. See KB article 219825 for troubleshooting steps.
2) If results are returned, ensure User Name and MAC address values are populated.
3) Proceed as appropriate:
User Name is missing: The proper syslog information was either not received or not processed. See KB article 219825 for troubleshooting steps.
MAC Address is missing: Agent information is either not received or not processed. See KB article 244783 for troubleshooting steps.
Record looks correct but client is not getting proper network access:
a) Confirm whether or not SSO tags have been sent to the FortiGate. In appliance CLI type
ssotool -ip <FortiGate IP>
The following information should be returned:
SSO sessions on device <FortiGate IP>:
Name: User name
IP: Remote IP address
Target: FortiGate IP
SubTarget: root
Tags: Tag sent by FortiNAC
Type: FORTINET
Connected: x
SSO messages in FNAC
Name: User name
IP: Remote IP address
Target: FortiGate IP
SubTarget: FortiGate IP
Tags: Tag sent by FortiNAC
Type: FORTINET_FSSO
Connected: x
b) If either the wrong tags or no tags were sent, see KB article 219917.
Contact Support for further assistance. Open a support ticket and provide the following:
- Software version (x.x.x.x).
- FortiGate version.
- Detailed description of behavior.
- Troubleshooting steps taken.
- IP address and username of test client.
- Timeframe behavior was reproduced.
- System logs (For instructions see KB article 190755).
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.