Last edited by Iqbal Hermawan Feb-12-2026 14:42.

Hi,
want to ask, if we want to apply configuration, example: applicatiion control & bandwidth management, do we need to activate license first ?

I would like to ask. Our IAG device has already been integrated with Active Directory (AD) and NAC. However, for the online users, only NAC users are being detected. The AD users are not appearing in the online user list.
Previously, the AD users were visible, but after one day they disappeared again.
Could you please advise on how to make the AD users consistently appear as online users?
Thank you in advance for your support.

By solving this question, you may help 633 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Newbie517762 Lv5Posted Feb-11-2026 17:33
  
HiHi,

Before the device is activated, you can only set up the network port to connect it to the public network. Other features, like application control and bandwidth management, won't work. To use those features, the device must be activated with a valid license first.
Muhammad Abid Lv2Posted Feb-11-2026 20:45
  
Yes — in Sangfor IAG, if you want to use features like:

Application Control
Bandwidth Management (Traffic Shaping / QoS)
You must have a valid and activated license first.

Why?

These features are part of advanced modules in IAG. Without an active license:
Application signatures database will not update.
Application identification may not work properly.
Policy enforcement (block/limit apps) may not apply correctly.
Bandwidth management linked with App Control may be limited.

What you should check
Go to:
System → License Management
Verify:
License Status = ✅ Activated
Application Control module = ✅ Enabled
Expiry date valid

Also check:
Signature database update status (Application feature library)



Muhammad Abid Lv2Posted Feb-13-2026 13:20
  
Most likely issue is AD identity mapping is stopping after some time.
Since NAC users are visible but AD users disappear, check these quickly in Sangfor IAG:

AD Server status = Connected
AD Agent service running on Domain Controller (restart it)
Time sync (NTP) between IAG and AD
Authentication policy priority (AD policy above bypass rules)
Session timeout not too short
In most cases, AD Agent service stops or time sync issue causes this.

If you tell me which authentication method you're using (AD Agent / NTLM / Portal), I’ll guide exact fix.

I Can Help:

Change

Moderator on This Board

917
183
94

Started Topics

Followers

Follow

Board Leaders