Typical workflow: Guest registers through captive portal or sponsor workflow. Temporary network access is granted. Guest account expires after the configured duration. Host becomes inactive. Aging policies remove stale users and hosts automatically.
Configure global aging settings:
Global aging settings determine how long host and user records remain in the FortiNAC-F database.
Navigate to System -> Settings -> User/Host Management -> Aging.
Steps:
Select System -> Settings. Expand User/Host Management. Select Aging. Configure the required settings. Select Save Settings.
Aging settings:
Setting | Purpose |
|---|
Days Valid | Number of days a host remains in the database. | Days Inactive | Number of inactive days before the host is removed. | Days Valid (Users) | Number of days a user remains in the database. | Days Inactive (Users) | Number of inactive days before the user is removed. | Delete hosts registered to user upon expiration | Removes associated hosts when the user expires. |
Important aging behavior:
Leaving aging fields empty disables global aging. Setting aging values to 0 removes the record during the next server poll cycle. Existing records with manually assigned expiration dates are not modified by global aging changes. Administrator accounts never expire automatically and must be removed manually.
Recommended aging examples:
Object Type | Typical Aging Period |
|---|
Guest devices | 14–30 days | Rogue hosts | 14–30 days | Corporate devices | 60–90 days |
Note: Fortinet recommends staggering large-scale aging operations to avoid processing spikes caused by simultaneous endpoint re-registration.
Guest expiration behavior.
Guest expiration is controlled by:
Account Duration settings, User expiration settings, Global aging policies.
Important behavior:
Guest users can age out automatically. Associated registered hosts can also be removed automatically. Host inactivity aging and user expiration aging operate independently. Host age timers are evaluated every 10 minutes. The user inactivity timer starts when all hosts registered to a user are seen as offline. When a host is seen as connected again, the inactivity timer is cleared. The inactivity timer is also cleared when the user logs into FortiNAC.
Configure host expiration manually: Navigate to Users & Hosts -> Hosts.
Steps:
Select the host. Right-click the host. Select Set Host Expiration Date.
Available options:
Specify Date Days Valid From Now Days Valid From Creation Days Inactive No Expiration Default Expiration
Configure user expiration manually:
Navigate to Users & Hosts -> User Accounts.
Steps:
Select the user. Right-click the user. Select Set User Expiration Date.
Available options:
Specify Date. Days Valid From Now. Days Inactive. No Expiration. Delete Registered Hosts.
Configure group-based host aging. FortiNAC-F supports group-based aging policies for host groups.
Navigate to System -> Groups.
Steps:
Right-click the host group. Select Set Aging. Configure:
This allows separate aging policies for the following: Important behavior:
If a host belongs to multiple groups, the aging policy applied is based on the last group to which the host was added or the last group whose aging settings were modified. Group-based aging applies only to host groups and does not apply to user groups.
Verify host and user aging:
Navigate to:
Review: Troubleshooting tips:
Guest accounts are not expiring:
Verify:
Guest hosts are not removed:
Check:
Hosts are removed too quickly:
Review:
Important: Adding aging settings to older records may immediately remove them if the calculated expiration date is already in the past. Setting aging values to 0 removes the record during the next server poll cycle.
Large database growth:
Review:
Best practices:
Use short expiration periods for guest devices. Enable inactive host aging. Review rogue host retention regularly. Use group-based aging where appropriate. Periodically review stale guest accounts and inactive hosts. Avoid setting aging values to 0 unless immediate removal is intended.
Conclusion:
Guest and BYOD environments can rapidly increase database growth in FortiNAC-F deployments.
Using:
Global aging settings, User expiration controls, Host inactivity aging, Group-based aging policies,
Helps maintain: Accurate endpoint visibility, Reduced database overhead, Faster GUI responsiveness, Improved operational stability.
Related articles:
|