05-22-2025 12:20 AM
We are using Cisco ISE as NAC solution and using posture, we have fortiAPs for wireless which are managed through fortigate.
We configured the radius on Fortigate, authentication is happening and posture assessment is working, but COA is not working. We have enabled the COA on fortigate, but fortigate is sending COANAK to ISE.Does anyone faced this problem and got it resolved ?
05-22-2025 04:43 AM - edited 05-22-2025 04:43 AM
- Check if these info's can help you : https://docs.fortinet.com/document/fortideceptor/5.3.1/administration-guide/894738/integrate-with-cisco-ise
M.
05-22-2025 05:00 AM
What is the COANAK reason? It should be in the ISE logs. What NAD profile are you using for the FortiGate? Most likely the CoA message is not formatted correctly with attributes the FortiGate does not understand.
05-22-2025 05:09 AM
COANAK reason is nasidentifier-mismatch. we are using Cisco device profile as we have not found anyfortinet device profile and vsa file.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide