FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 197521
Description
Inconsistent Policy Assignment Moving Between Aerohive Networks

Scope
Version: All
Solution
Version: All

Issue:  When Aerohive wireless clients move between AP's using different networks, Network Sentry does not consistently assign the correct network access policy, causing the wrong VLAN to be assigned.  Network Access Policy Host/User Profile is configured to match certain AP's in the adapter location of the "Who/What by Attribute" setting.

Network Sentry processes the adapter location after the assignment of the network access policy.  Therefore, the adapter information will not be accurate at the time the system is trying to match a Network Access policy.

Solution: Assign based on port group instead of adapter location. 
1) Create (port) groups that include the appropriate SSID for all the AP's that are members of that particular location.
2) Add this group to the "Where (Location)" section of the User/Host Profile.
3) Remove the Host location attribute of the User/Host profile.
 


Contributors