Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
eascolaro
New Contributor

No Internet access when switching IP's

Hi,

 

We currently have a Single Sign-On Agent installed on 1 DC, which is configured to monitor all DC's.

 

All works fine until a users switches from wired Ethernet to Wifi, they are no longer able to browse the internet. To solve this, they would need to lock the laptop and log-in again to windows.  In the "Show Logon Users" the user will be listed with "wired" IP address and not Wifi IP.

 

 

I have tried reducing the "Workstation verify interval" to 1 minutes and the "IP address change verify interval" to 10 seconds but this did not solve the problem. 

 

Firmware: v5.2.7,build718 on 300D

1 Solution
Fishbone_FTNT

Hi eascolaro,

it heavily depends on DNS. Wifi adapter has to be able to send DNS update to DNS server you are using. 

 

The feature used in this case is "IP change detection". It walks in the loop the logon list, and tries to resolve workstation name there. So if you move to Wifi, you must ensure DNS update reaches DNS server, it's reflected and DNS database is updated. Then, IP change detection feature will resolve workstation name correctly, containing fresh IP address and logon list is updated.

 

Fishbone )(

 

smithproxy hacker - www.smithproxy.org

View solution in original post

12 REPLIES 12
xsilver_FTNT

Hi,

check or retest and pay extra attention to time when step 3) happened and what happened after in eventlog and Collector debug log.

If you just changed IP and re-connected cable.

Then if wifi was not disconnected then you should have 2 IP addresses on NTB > 2 IP in DNS.

If that change was not followed by any logon event spotted (time of "3)" step and later), then Collector will take up to "3)"+"registry DNSlookupinterval" (in GUI as "IP Address change verify interval (seconds)") time to realize that IP has changed.

Check sequences.

Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

eascolaro

Hi Thomas,

 

The laptops are configured to disconnect Wi-Fi when Ethernet is connected. And when it senses the cable is unplugged it reconnects to Wi-Fi.

eascolaro

And even so, the "IP Address change verify interval (seconds)" is set to 10 seconds. So it should verify the IP after 10sec, 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors