Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Rabeb_Ali
New Contributor II

How to handle MAB locally in FortiNAC ?

Hello Community,

When FortiNAC is in proxy mode, the PC authenticates successfully but the IP phone MAB requests are always forwarded to Radius Server and rejected.

I  tried to create an authentication policy to override this behavior and force local MAB authentication on FortiNAC, but it did not work.

Is it possible to handle MAB locally while FortiNAC is running in proxy mode?

7 REPLIES 7
AEK
SuperUser
SuperUser

Ha Rabeb

If I remember well I was used to configure on FNAC both RADIUS proxy and local RADIUS at the same time. Only thing needed is to change the listening port of one of them, e.g.: use legacy port 1645 for local RADIUS.

AEK
AEK
ebilcari
Staff
Staff

Check if this setup has the option 'Proxy MAB Requests' enabled like shown below:

 

proxymab.PNG

By default, this option is disabled. Authentication policies are not related to RADIUS authentication requests originating from NAS devices.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Rabeb_Ali
New Contributor II

thank you for your replies, the proxy MAB Requests is enabled and the RADIUS server is configured to listen on port 1645, but MAB requests from IP phones are still not handled locally by FortiNAC and continue to be forwarded to NPS and rejected

AEK

It means you shouldn't proxy the MAB requests, but treat them locally.

AEK
AEK
Rabeb_Ali
New Contributor II

Exactly, that is my issue. I want FortiNAC to process MAB requests locally and not proxy them

ebilcari

Than you should disable that option, if the requirement is to process them locally.
In recent version of FNAC, only a single authentication port is used for local and proxy requests. The requests are than routed accordingly.
It is also suggested to have at least one local server configured in Virtual Servers.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
mrsimon007
New Contributor III

Is it possible to configure FortiNAC to process MAB authentication locally for IP phones while operating in proxy mode, instead of forwarding MAB requests to the RADIUS server?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors