Skip to main content
unknown1020
Explorer III
October 26, 2023
Question

Device in FortiNac

  • October 26, 2023
  • 6 replies
  • 2193 views

Friends, a question, does a "rogue" device mean a device not registered with Fortinac?

since in Dashboard >> Main >> Endpoint Fingerprints shows information about "Rogue

 

6 replies

Sheikh
Staff
Staff
October 26, 2023

Hello @unknown1020 

 

As per admin guide, Rogues are those devices that do not match any of the rules enabled in the device profiling rules. You may also have hosts that have been categorized incorrectly.

 

So if you have such hosts then please check EPC policies and other relevant Policies e.g. Network Access policies.

 

You can also right click the host and check Policy Details anf then check EPC Policies status.

 

regards,

 

Sheikh

If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.
ebilcari
Staff
Staff
October 27, 2023

The definition of rouge in FNAC is a physical address that has been seen on the network but has not been associated with an existing known host and is therefore considered unknown. There are several ways to register hosts like Device profiling, through web portal, dot1x auto registration through RADIUS information, manual registration, import etc.

 

In the Endpoint Fingerprints menu you may find all the MAC addresses learned by FNAC and the source of that information. Same MAC address can also be shown multiple times to keep it as a reference when the source is different. There is also the "Set Source Rank" option that shows which Source is considered more "trustworthy" than can override the information.

finberprint.PNG

Emirjon
unknown1020
Explorer III
October 30, 2023

Rogue are the device that do not communicate with the fortinac or the unregistered device? Since the report indicates "last communication"

ebilcari
Staff
Staff
October 31, 2023

Every host/device need to communicate with FNAC even when they are isolated through FNAC's isolation interface for different reasons:

Rouge - will have to be classified (active mode)

At-Risk - need to be remediated and update their compliance status

Authentication - user need to authenticate

Dead-end - (optional) only to show the portal and notify the end host

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!