Skip to main content
sjoshi
Staff
Staff
June 25, 2026

Technical Tip: Optimizing endpoint classification with multiple on-fabric detection rules under a single endpoint policy

  • June 25, 2026
  • 0 replies
  • 12 views

Description

This article describes how to configure multiple on-fabric detection rules within a single endpoint policy to optimize endpoint classification and policy enforcement.

Scope

FortiClient EMS.

Solution

There may be scenarios where certain sites use dynamic public IP addresses, making on-fabric detection based on public IP monitoring unsuitable. In these cases, different on-fabric detection rules should be implemented to ensure reliable endpoint classification.

Create two on-fabric detection rules: one based on public IP for standard sites, and another based on local subnet for sites with dynamic public IP addresses.

a1631bb0.png


Both on-fabric detection rules can be associated with a single endpoint policy in FortiClient EMS. As a result, endpoints matching either rule will be placed under the same policy, maintaining uniform policy enforcement and security restrictions.

4e648602.png


Once the rule has been saved and applied to the policy, the endpoints will start matching the on-fabric detection rule and a single endpoint policy can be used for multiple on-fabric detection rules.

This will be the 'OR' rule: any endpoints matching either of the rules will be considered as on-fabric devices.

7c1ad2f4.png