Technical Tip: How to configure FortiNAC to send SSO tags to a Downstream FortiGate in a Security Fabric
| Description | This article describes how to configure FortiNAC to send SSO tags to a Downstream FortiGate in a Security Fabric environment. |
| Scope | FortiNAC -F, FortiNAC. |
| Solution | In a Security Fabric environment, if FortiNAC learns a host from a downstream FortiGate, It can send SSO tags to the downstream FortiGate. It is not necessary to establish a Security Fabric connection directly between FortiNAC and the Downstream FortiGate; FortiNAC can send SSO tags to the Downstream FortiGate via the Security Fabric root FortiGate connector.
Configure Security Fabric Root FortiGate.
The Security Fabric root FortiGate configuration in CLI is like the one below.
Configure Security Fabric downstream FortiGate.
The Security Fabric downstream FortiGate configuration in CLI is like the one below.
config system csf set status enable set uid "4863100b4cbfc383d3ff39380a2b0c1e" set upstream "10.191.20.203" set downstream-access enable set downstream-accprofile "super_admin" end Configure FortiNAC security Fabric connector with Root FortiGate.
Configure Downstream FortiGate configuration in FortiNAC.
Whenever a host is learned from Downstream FortiGate and matches the appropriate Network Access Policy, FortiNAC sends SSO tags to Downstream FortiGate.
Related articles: |








