Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Tip: Device Being Scanned by FortiNAC

  • September 28, 2018
  • 0 replies
  • 1091 views

Description

 

This article discusses the behavior where an antivirus program on an endstation is reporting FortiNAC running a scan on a large number of ports. This can occur if Device Profiling Rules are configured to use the 'Active' method to identify rogues or re-validate hosts.
 
Scope
 
FortiNAC/CentOS 9.x, 7.2, FortiNAC-F/FortiNAC-OS 7.2

Solution

The 'Active' method scans a large number of ports to identify the device type.  The port scan is normal behavior but may trigger some Antivirus programs to report this as a potential network attack. 

Note
If the 'Confirm Rule on Connect' option is enabled in the Device Profiling Rule, registered devices previously profiled with this rule will be scanned each time they connect to the network.  This function is used to confirm the device still matches the rule.
 
26.09.2025_10.56.14_REC.png

    

See Adding a rule in the Administration Guide for a complete list of available methods for device identification. 
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!