Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mzougaghe
New Contributor

FortiNAC 802.1X – Dynamic VLAN Assignment Based on AD Groups

I’ve configured FortiNAC-F as a local RADIUS server and successfully joined it to my Active Directory using Winbind.

Currently, I have a network access policy that places all 802.1X users into the LAN Network, and it’s working as expected.

 

Now, I’d like to set up access policies that dynamically assign VLANs based on the user’s Active Directory group membership:

  • If a user belongs to AD IT_GROUPE, they should be placed in the IT Network.

  • If a user belongs to AD USERS_GROUPE, they should be placed in the LAN Network.

 

mohamed zougaghe
mohamed zougaghe
2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Mohamed

First you should prepare two UHP (User Host Profiles). In the first you select IT_GROUP in the WHO field, and in the second UHP you select USERS_GROUP in the same field. You can also use User Roles instead.

The use these two UHP to build two Access Policies and select for each the appropriate networks as target.

AEK
AEK
mzougaghe
New Contributor

 

Hi AEK,

Thank you for your reply.

In the WHO field, I don’t see an option for AD Group—only user attributes such as first name, last name, city, etc., are available.

Here’s what I’ve tried so far (unsuccessfully):

  1. Created a role: IT_ROLE, which includes the AD group IT_GROUP.

  2. Created a UHP: IT_UHP, configured to match users with the role IT_ROLE AND using PEAP as the RADIUS authentication method.

  3. Configured Network Access: to assign users to the IT network if they match IT_UHP.

Unfortunately, this setup isn't working as expected. Any insights on what might be missing or misconfigured?

Thanks again for your help!

 

mohamed zougaghe
mohamed zougaghe
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors