<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to configure restriction for non compliant wireless user  in in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5345704#M598858</link>
    <description>&lt;P&gt;Is there any reference link to implement this solution.&lt;/P&gt;
&lt;P&gt;We have configure AD as identity source on ISE for authentication .&lt;/P&gt;
&lt;P&gt;Then how we can call group from fortigate is it will initiate authentication again?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Nov 2025 05:42:50 GMT</pubDate>
    <dc:creator>ravina-gurav</dc:creator>
    <dc:date>2025-11-10T05:42:50Z</dc:date>
    <item>
      <title>Need to configure restriction for non compliant wireless user  in ise</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344666#M598813</link>
      <description>&lt;P&gt;We have FortiGate WLC for wireless user .&lt;/P&gt;
&lt;P&gt;After posture scanning if the user is non-compliant we are unable to restrict the access user is getting full access.&lt;/P&gt;
&lt;P&gt;We tried from ISE to Push ACL still the restriction is not working.&lt;/P&gt;
&lt;P&gt;Wireless user connecting through fortiAP.&lt;/P&gt;
&lt;P&gt;Is there any solution we can configure restriction for non-compliant user as fortigate is the NAD device for user.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Nov 2025 10:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344666#M598813</guid>
      <dc:creator>ravina-gurav</dc:creator>
      <dc:date>2025-11-05T10:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need to configure restriction for non compliant wireless user  in</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344691#M598814</link>
      <description>&lt;P&gt;I've never done it before, so bear with me please. It seems you could do it using RADIUS "NAS-Filter-Rule" attribute as it states here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-issue-i-cannot-input-any-value-on-radius-nas-filter-rule/td-p/3950991" target="_blank"&gt;Solved: ISE issue :i cannot input any value on Radius:NAS-Filter-Rule - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/cb85917a-1b07-11f0-b13a-ca4255feedd9/FortiWiFi_and_FortiAP-7.6.3-Configuration_Guide.pdf" target="_blank"&gt;FortiWiFi and FortiAP Configuration Guide&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Nov 2025 11:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344691#M598814</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-11-05T11:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Need to configure restriction for non compliant wireless user  in</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344765#M598821</link>
      <description>&lt;P&gt;&lt;A href="https://cs.co/ise-berg#fortinet" target="_blank"&gt;https://cs.co/ise-berg#fortinet&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How is the FortiAP managed? You should pass a User Group attribute if managed by a FortiGate instead.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Nov 2025 15:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344765#M598821</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-11-05T15:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Need to configure restriction for non compliant wireless user  in</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344896#M598825</link>
      <description>&lt;P&gt;Managed By Fortigate.&lt;/P&gt;
&lt;P&gt;I am Using AD for user authentication.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 06:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344896#M598825</guid>
      <dc:creator>ravina-gurav</dc:creator>
      <dc:date>2025-11-06T06:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Need to configure restriction for non compliant wireless user  in</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344934#M598827</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1817382"&gt;@ravina-gurav&lt;/a&gt;&amp;nbsp;&lt;A href="https://www.ezpassn-j.com" target="_self"&gt;E-ZPass New Jersey&lt;/A&gt;wrote:&lt;BR /&gt;&lt;P&gt;We have FortiGate WLC for wireless user .&lt;/P&gt;&lt;P&gt;After posture scanning if the user is non-compliant we are unable to restrict the access user is getting full access.&lt;/P&gt;&lt;P&gt;We tried from ISE to Push ACL still the restriction is not working.&lt;/P&gt;&lt;P&gt;Wireless user connecting through fortiAP.&lt;/P&gt;&lt;P&gt;Is there any solution we can configure restriction for non-compliant user as fortigate is the NAD device for user.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The failure to enforce restrictions on non-compliant users via your FortiGate WLC (acting as the NAD) with Cisco ISE is likely due to a **Vendor-Specific Attribute (VSA) or Change of Authorization (CoA) mismatch**. The FortiGate is likely ignoring the ACL pushed by ISE because it doesn't understand the format. The solution requires ensuring **CoA is properly configured and acknowledged** by the FortiGate, and crucially, configuring the **Non-Compliant Authorization Profile in ISE to send a specific Fortinet VSA** (e.g., `Fortinet-Group-Name`) instead of a standard ACL. The FortiGate can then map this received VSA to a local **Firewall User Group** with a restrictive policy.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 07:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5344934#M598827</guid>
      <dc:creator>mary58wilson</dc:creator>
      <dc:date>2025-11-06T07:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Need to configure restriction for non compliant wireless user  in</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5345016#M598837</link>
      <description>&lt;P&gt;No one should be using MS-CHAPv2 in 2025. It relies on broken encryption. are you disabling credential guard?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 13:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5345016#M598837</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-11-06T13:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Need to configure restriction for non compliant wireless user  in</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5345704#M598858</link>
      <description>&lt;P&gt;Is there any reference link to implement this solution.&lt;/P&gt;
&lt;P&gt;We have configure AD as identity source on ISE for authentication .&lt;/P&gt;
&lt;P&gt;Then how we can call group from fortigate is it will initiate authentication again?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 05:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5345704#M598858</guid>
      <dc:creator>ravina-gurav</dc:creator>
      <dc:date>2025-11-10T05:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Need to configure restriction for non compliant wireless user  in</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5345715#M598859</link>
      <description>&lt;P&gt;As said further up in the thread, you need to import the Fortinet VSAs into ISE as a dictionary. You can find the VSAs here: &lt;A href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-Fortinet-RADIUS-vendor-specific-attributes-VSAs/ta-p/191592?externalId=13837" target="_blank"&gt;Fortinet RADIUS vendor-specific attribute... - Fortinet Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;To quote the process of importing Fortinet VSAs into ISE from this post (all credits to original author):&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/fortigate-authorization-with-ise/td-p/3545350" target="_blank"&gt;Solved: Fortigate authorization with ISE - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;1) Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Dictionaries&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;2) In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Dictionaries&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;left panel, choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;System &amp;gt; RADIUS &amp;gt; RADIUS Vendors&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bweber1_0-1762755353577.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/254954iFC9A305C05CA202B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bweber1_0-1762755353577.png" alt="bweber1_0-1762755353577.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) You should see a list of RADIUS Vendors that&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;does not&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;include&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Fortinet&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;4) Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Import&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;5)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Browse...&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Fortinet_VSAs.txt&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file then click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Import&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;button and acknowledge the dialog to import the file. (&lt;STRONG&gt;Note:&amp;nbsp;&lt;/STRONG&gt;You will have to create this file or copy it from the linked post).&lt;/P&gt;
&lt;P&gt;6) You should now see Fortinet in the RADIUS Vendors list:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bweber1_1-1762755353579.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/254952i18D459174155C29A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bweber1_1-1762755353579.png" alt="bweber1_1-1762755353579.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and all of the Fortinet attributes listed under the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Dictionary Attributes&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bweber1_2-1762755353583.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/254951i244A7E5B6FDD4FBA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bweber1_2-1762755353583.png" alt="bweber1_2-1762755353583.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 06:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-configure-restriction-for-non-compliant-wireless-user-in/m-p/5345715#M598859</guid>
      <dc:creator>Ben Weber</dc:creator>
      <dc:date>2025-11-10T06:17:39Z</dc:date>
    </item>
  </channel>
</rss>

