We are currently in the process of testing / deploying wired enforcement at our organization. One issue we are running into is receiving MAC Traps from FortiFones when a device is plugged into the passthrough port of the phone.
MAC-Trap notifications have been configured on all switch ports throughout our deployment. The parameters of those MAC-Traps are set to send notifications directly to the FortiNAC servers when a MAC address changes on a switch port (device is plugged in / unplugged). This functionality works as intended when plugging and unplugging directly from the switch port. This is to notify the FortiNAC of the device change on the port so that the FortiNAC can reset the port to a default configured VLAN and/or evaluate the new device against network policy.
We are running ArubaOS switches, but as far as I can tell, this is an issue with the phone not sending a trap when the device disconnects. Thoughts? Thanks in advance. |
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
This is expected behviour. The issue is the switchport does not go down when the device behind the phone is unplugged. Therefore you are waiting for the MAC address to age out of the switch's table. This is outlined in the Congiuring MAC Traps documentation: https://docs.fortinet.com/document/fortinac/9.4.0/configuring-traps-for-mac-notification
Are there issues with having the devices in the database even after they are physically disconnected?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1703 | |
1092 | |
752 | |
446 | |
229 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.