Fortinet white logo
Fortinet white logo
7.4.0

Scenario 2: Custom – Basics

Scenario 2: Custom – Basics

Use custom RFC5176 mode if you want FortiNAC to send a customized Disconnect or COA message.

In this example, to force FortiSwitch to reauthenticate the port, we are using the following settings:

  • RFC5176 Message Type: CoA Message

  • RFC5176 Attribute Group: FSW_CoA_Reauth which includes the below attributes

    • Fortinet-Host-Port-AVPair: action=reauth-port

    • Calling-Station-Id: %AUTH%

  • Other RFC5176 settings in both Device Level and logical network are default values.

When the host is disabled, a COA request with action=reauth-port will be sent, and the FortiSwitch will reply with a COA-ACK message.

The host will reauthenticate and be assigned to Dead End VLAN (in our case, it’s VLAN 11).

Scenario 2: Custom – Basics

Scenario 2: Custom – Basics

Use custom RFC5176 mode if you want FortiNAC to send a customized Disconnect or COA message.

In this example, to force FortiSwitch to reauthenticate the port, we are using the following settings:

  • RFC5176 Message Type: CoA Message

  • RFC5176 Attribute Group: FSW_CoA_Reauth which includes the below attributes

    • Fortinet-Host-Port-AVPair: action=reauth-port

    • Calling-Station-Id: %AUTH%

  • Other RFC5176 settings in both Device Level and logical network are default values.

When the host is disabled, a COA request with action=reauth-port will be sent, and the FortiSwitch will reply with a COA-ACK message.

The host will reauthenticate and be assigned to Dead End VLAN (in our case, it’s VLAN 11).