FortiNAC uses a rule-based profiling engine enhanced by FortiGuard IoT intelligence, which provides:
Behavioral analysis complements this by evaluating:
Components: FortiNAC-F (Profiler + Policy Engine). FortiGuard IoT cloud service. Network infrastructure (Switches/APs/Firewalls). IoT / OT endpoints.
FortiNAC can gather information about the connected devices from multiple sources within the network.
 Profiling workflow:
Step-by-step process. Device connects → identified as a Rogue device.
FortiNAC collects attributes: MAC address (OUI). DHCP fingerprint. Traffic data.
FortiGuard IoT lookup performed.
Behavioral indicators evaluated: Ports. Protocols. Communication patterns.
Profiling rules correlate: Local attributes. FortiGuard data.
Device classified with: Policy enforcement applied.
Enable Device Profiling:
Log in to the FortiNAC-F GUI console. Expand System -> Select Settings ->Select User/Host Management -> Select Device Profiler.
 Example rule: Smart camera.
Conditions: FortiGuard Category = Camera. Vendor OUI = Axis / Hikvision. Open Port = 554 (RTSP). HTTP response contains a camera signature.
Actions: Type: Camera. Role: IoT_Camera. Register as: Host.
Log in to the FortiNAC GUI console. Expand Users & Hosts -> Select Device Profiling Rules -> Select Add to create a device profiling rule.



 It is recommended to use multiple profiling methods for accuracy.
Scenario 1: IP Camera.
Classified as Camera. Scenario 2: Printer.
Classified as Printer. Scenario 3: PLC (OT Device).
Classified as an Industrial Device. Policy enforcement.
Once classified: Example:
Device Type | VLAN | Access |
|---|
Camera | VLAN 30 | Limited | Printer | VLAN 20 | Internal only | PLC | VLAN 40 | Restricted |
Best practices:
FortiGuard-based. OUI. Behavioral. Active scanning.
Avoid:
Single-method rules. Overlapping conditions. Excessive active scans.
Troubleshooting.
Issue: Device not classified.
Issue: Incorrect classification. Issue: No FortiGuard data.
Related documents:
Technical Tip: Device profiling using the SNMP method Device Profiling rules Technical Tip: Device profiling methods for IoT/OT devices and nmap scanning |