Skip to main content
scitlak
Staff
Staff
December 19, 2024

Technical Tip: How to configure FortiNAC to send SSO tags to a Downstream FortiGate in a Security Fabric

  • December 19, 2024
  • 0 replies
  • 435 views
Description This article describes how to configure FortiNAC to send SSO tags to a Downstream FortiGate in a Security Fabric environment.
Scope FortiNAC -F, FortiNAC.
Solution

In a Security Fabric environment, if FortiNAC learns a host from a downstream FortiGate, It can send SSO tags to the downstream FortiGate. It is not necessary to establish a Security Fabric connection directly between FortiNAC and the Downstream FortiGate; FortiNAC can send SSO tags to the Downstream FortiGate via the Security Fabric root FortiGate connector.


18.12.2024_16.20.40_REC.png

 

Configure Security Fabric Root FortiGate.


19.12.2024_09.45.58_REC.png

 

The Security Fabric root FortiGate configuration in CLI is like the one below.


config system csf
    set status enable
    set uid "ce0d2c9ac0961f0d9e9f98cbc11582f2"
    set group-name "fnac"
    set downstream-access enable
    set downstream-accprofile "super_admin"
        config trusted-list
            edit "FNVXXXXXXXXXXXX"
                set serial "FNVXXXXXXXXXXXX"
                set index 2
            next
            edit "FGXXXXXXXXXXX"
                set serial "FGXXXXXXXXXXXX"
                set index 1
            next
        end
end

 Configure Security Fabric downstream FortiGate.

19.12.2024_09.52.49_REC.png

 

The Security Fabric downstream FortiGate configuration in CLI is like the one below.

 

config system csf

    set status enable

    set uid "4863100b4cbfc383d3ff39380a2b0c1e"

    set upstream "10.191.20.203"

    set downstream-access enable

    set downstream-accprofile "super_admin"

end

Configure FortiNAC security Fabric connector with Root FortiGate.

19.12.2024_09.55.19_REC.png

 

Configure Downstream FortiGate configuration in FortiNAC.

19.12.2024_09.56.21_REC.png

 

Whenever a host is learned from Downstream FortiGate and matches the appropriate Network Access Policy, FortiNAC sends SSO tags to Downstream FortiGate.


19.12.2024_09.59.17_REC.png

 

19.12.2024_09.59.48_REC.png

 

19.12.2024_10.00.36_REC.png

 

Related articles:
Troubleshooting Tip: Dynamic Firewall address object is not getting created due to '401 Unauthorized' in FortiNAC integration with FortiGate 
Technical Tip: Configure Security Fabric with FortiNAC & FortiGate

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.