Technical Tip: Configuring Dead End as Enforcement
Description
This article describes the configurations needed to isolate disabled hosts to the Dead End network. This enforcement status can not be configured as Port Group Membership which is usually used for another type of enforcement but needs to be configured at the device level.
Scope
FortiNAC.
Solution
- Configure the Dead End for the Logical network in Model Configuration at the network device level (FortiSwitch/FortiAP/FortiGate or SSID):
FortiGate (virtualized device):

FortiSwitch/FortiWLC:

 
SSID Configuration:

 
- Add the new network devices as part of the group 'Physical Address Filtering'. This is configured in System -> Groups, find this specific group and add the network devices as members:

 
The same result can be obtained by 'right-clicking' on the device and making it a member of this group:

 
Now all the ports of that device will have the Dead End enforced on every port:

 
If a disabled host is connected to this port, it will be moved to the Dead End VLAN:

On the end host's browser, the user gets notified of this action through the portal:

 
Related document:
