Skip to main content
FortiKoala
Staff
Staff
September 27, 2018

Technical Tip: Disabled wireless hosts not isolated

  • September 27, 2018
  • 0 replies
  • 1189 views

Description


This article describes a wireless Host marked as disabled but still able to connect to the production network.

 

Scope


FortiNAC.

 

Solution

 

Ensure the Dead-End role/VLAN is configured in the AP model and the state is enforced.
 
  1. In the Administration UI, navigate to Network -> Inventory.
  2. Select on the Controller/AP Mode.
  3. Select the Model Configuration tab or select on the SSIDs tab, right click on the applicable SSID and select SSID Configuration.
  4. Set state for Dead End to Enforce, and Access Value to the role/VLAN designated for Dead-End isolation.
  5. Save.
 
 
deadSSID.png
 
Related articles: