Scenario 2: Custom – Basics
Use custom RFC5176 mode if you want FortiNAC to send a customized Disconnect or COA message.
In this example, to force FortiSwitch to reauthenticate the port, we are using the following settings:
-
RFC5176 Message Type: CoA Message
-
RFC5176 Attribute Group: FSW_CoA_Reauth which includes the below attributes
-
Fortinet-Host-Port-AVPair: action=reauth-port
-
Calling-Station-Id: %AUTH%
-
-
Other RFC5176 settings in both Device Level and logical network are default values.
When the host is disabled, a COA request with action=reauth-port
will be sent, and the FortiSwitch will reply with a COA-ACK message.
The host will reauthenticate and be assigned to Dead End VLAN (in our case, it’s VLAN 11).