Hello Community,
When FortiNAC is in proxy mode, the PC authenticates successfully but the IP phone MAB requests are always forwarded to Radius Server and rejected.
I tried to create an authentication policy to override this behavior and force local MAB authentication on FortiNAC, but it did not work.
Is it possible to handle MAB locally while FortiNAC is running in proxy mode?
Ha Rabeb
If I remember well I was used to configure on FNAC both RADIUS proxy and local RADIUS at the same time. Only thing needed is to change the listening port of one of them, e.g.: use legacy port 1645 for local RADIUS.
Check if this setup has the option 'Proxy MAB Requests' enabled like shown below:
By default, this option is disabled. Authentication policies are not related to RADIUS authentication requests originating from NAS devices.
thank you for your replies, the proxy MAB Requests is enabled and the RADIUS server is configured to listen on port 1645, but MAB requests from IP phones are still not handled locally by FortiNAC and continue to be forwarded to NPS and rejected
It means you shouldn't proxy the MAB requests, but treat them locally.
Exactly, that is my issue. I want FortiNAC to process MAB requests locally and not proxy them
Created on 12-24-2025 05:18 AM Edited on 12-24-2025 05:21 AM
Than you should disable that option, if the requirement is to process them locally.
In recent version of FNAC, only a single authentication port is used for local and proxy requests. The requests are than routed accordingly.
It is also suggested to have at least one local server configured in Virtual Servers.
Is it possible to configure FortiNAC to process MAB authentication locally for IP phones while operating in proxy mode, instead of forwarding MAB requests to the RADIUS server?
| User | Count |
|---|---|
| 2881 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.