Technical Tip: Optimizing endpoint classification with multiple on-fabric detection rules under a single endpoint policy
Description
This article describes how to configure multiple on-fabric detection rules within a single endpoint policy to optimize endpoint classification and policy enforcement.
Scope
FortiClient EMS.
Solution
There may be scenarios where certain sites use dynamic public IP addresses, making on-fabric detection based on public IP monitoring unsuitable. In these cases, different on-fabric detection rules should be implemented to ensure reliable endpoint classification.
Create two on-fabric detection rules: one based on public IP for standard sites, and another based on local subnet for sites with dynamic public IP addresses.

Both on-fabric detection rules can be associated with a single endpoint policy in FortiClient EMS. As a result, endpoints matching either rule will be placed under the same policy, maintaining uniform policy enforcement and security restrictions.

Once the rule has been saved and applied to the policy, the endpoints will start matching the on-fabric detection rule and a single endpoint policy can be used for multiple on-fabric detection rules.
This will be the 'OR' rule: any endpoints matching either of the rules will be considered as on-fabric devices.

