FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 192596
Description
Controller rejecting authentication response from the appliance in L2 High Availability configuration.  Controller's AAA Server configuration contains Network Sentry's VIP (Virtual IP).

The appliance responds to RADIUS requests using the physical eth0 IP address (regardless of High Availability configuration).  The controller will not accept a response from an IP address that is not defined in the AAA Server configuration.

Scope
Version:  8, 9

Solution
The following must be configured on the controller:
  • 2 AAA Server configurations: one for the Primary Control Server IP and one for the Secondary Control Server IP.
  • Fail over to Secondary when Primary does not respond (Round Robin cannot be used).
Refer to the appropriate integration guide for more details regarding configuration.




Contributors