Hello Community,
I am facing an issue with FortiNAC policy matching and VLAN enforcement.
Environment:
FortiNAC F
Juniper switch (dot1x authenticator)
Current Behavior: On the switch, the session is shown as Authenticated via RADIUS. VLAN assignment only works when I manually force the Registration or Authentication VLANs.
However, FortiNAC displays the following:
Auth Type: MAB
No policy matched
This occurs even though the Network Access Policy is configured with:
RADIUS Auth Type: 802.1X
Groups: UsersGroup
Locations: Any
Observations: MAC-RADIUS is enabled on the switch interface. Although the device is configured for 802.1X authentication and FortiNAC correctly learns the user identity (DOMAIN\username), FortiNAC does not seem to classify the session as 802.1X, only as MAB. Port Group Membership shows Role Based Access is enabled, but no policy hit is recorded.
What checks or actions can be performed to resolve this classification issue?
| User | Count |
|---|---|
| 2862 | |
| 1445 | |
| 829 | |
| 820 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.