Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BarryGhuman
New Contributor

FortiNAC to send the Cisco radius Neat attribute

Hi Team, 

 

I am replacing Cisco ISE with FortiNAC. The Cisco ISE is currently configured to profile the Access Points and send a Cisco Neat attribute. This Neat attribute helps the Cisco switch assign a truck role to the port. 

 

In FortiNAC, Network Access > "Configuration" - It does not provide any option to send radius attribute only and VLAN ID is mandatory. 

https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116681-config-neat-cise-00.html

 

cisco-avpair = device-traffic-class = Switch

 

I want to check if FortiNAC has a way to sort this situation. 

 

Regards, 

Barry Ghuman 

3 REPLIES 3
ebilcari
Staff
Staff

Yes, it's possible through custom Attribute Groups. You can also check this article that shows a similar setup.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
BarryGhuman

Hi Team, 

I think you didn't understand my question. I want to assign only Radius attributes. I don't want to send the mandatory VLAN attribute. 

 

Regards, 

Barry Ghuman

 

 

 

raghuwar2
New Contributor

Yup. The problem is, it is not matching only this host profile, if i change the host profile to not have radius attribute filter it is correctly matching.

Wifi integration with FAPs is in place and working. Its really dissapointing that I cant match attributes as it is the most basic feature of radius policy servers.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors