FortiNAC-F
FortiNAC-F is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks. For legacy FortiNAC articles prior to FortiNAC-F 7.2, see FortiNAC.
khoffman
Staff
Staff
Article Id 306523
Description This article describes how to view local RADIUS authentication logs from GUI.
Scope FortiNAC-F v7.2, FortiNAC v9.4.
Solution
  1. From the Admin GUI, navigate to Network -> RADIUS.
  2. From the 'Local Service' view, enable Debug & Troubleshooting

 

LocalRADIUSDebug.png

 

  1. Enable logging options: 
  • Service Log Level: Enables radiusd service to debug. Normal is recommended for most debugging. Select 'view logs' (Service log) to view debug output. 
  • Service Debug Host MAC Filter (Optional): Scope service debug information to one or more (comma-separated) host MAC addresses. 
  • FortiNAC Server Log Debug: Enable FortiNAC server debug related to Local RADIUS processing. This is useful when authentication requests successfully make it to the port-auth state. Select 'View Logs' (Server Log) to view the FortiNAC RADIUS debug output.
  • Include Network Access Policy Debug: Lookup details to troubleshoot problems matching the proper Network Access Policy. For other post-auth issues. Leaving this option disabled is recommended for better readability. 

  1. Select 'Submit' to enable debugging.
  2. Select 'View Logs' to view the RADIUS logging enabled.
  3. Disable the 'Enable logging' option once debugging is completed. For a best performance, disable the local radius service debug once troubleshooting is complete. 
  4. Select 'Submit'. 


Debugging output from both Service logs and Server Logs are collected in a log snapshot

Related article: 

Local RADIUS Server

Contributors