Skip to main content
Markus_M
Staff & Editor
Staff & Editor
March 3, 2020

Technical Tip: FortiNAC - FortiGate firewall session polling

  • March 3, 2020
  • 0 replies
  • 3100 views

Description


This article describes how to configure FortiNAC and FortiGate to poll the sessions to FortiNAC.


Scope

 

  • SSH needs to be enabled on the FortiGate.
  • User with full permissions (super_admin) on FortiGate.
  • At least SNMPv1 needs to be enabled and configured on FortiGate.
  • Firewall Polling needs to be enabled on FortiNAC.

 

Solution

 

  1. Enable and configure SNMP Agent on FortiGate.

 

 

 
  1. Create new Community for FortiNAC by selecting '+ Create New' and configure the following.
 
 
  • Specify the Community Name.
  • Enter the IP address from FortiNAC to 'IP Address' field

 

 

  1. FortiGate to FortiNAC in the 'Network Devices' under Topology'.

 

 

 
  1. Make sure SSH credentials and SNMP are validated and confirmed.
 
 
  1. Select the FortiGate and select 'Set Firewall Session Polling'.
 
 
  1. Make sure 'Enabled' is selected and write the 'Frequency' interval and select OK to save. Manually poll the unit by selecting 'Poll now'.

 

MRK-1.jpg
 
  1. After a couple of minutes, the sessions listed under Hosts -> FortiGate Sessions becomes visible.
MRK-2.jpg
 
Troubleshooting.
 
  1. If there are no sessions listed when 'FortiGate Sessions' is open, try to refresh the list with a refresh button in the top right corner.
 
 
  1. Verify that the FortiGate is being polled properly.

MRK-3.jpg


Note:

FortiNAC reads the IPv4 Firewall sessions. It reads /api/v2/monitor/firewall/session from the FortiOS REST API.

 

Related documents:
Troubleshooting Tip: The L2 polling for the FortiGate is frequently failing in FortiNAC. 
General Configuration 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!