Skip to main content
mrimmune
New Member
June 28, 2024
Question

Fortiswitch NAC user policy identification

  • June 28, 2024
  • 4 replies
  • 1418 views

Hello team.

What kind of users can be used in FortiSwitch NAC user policy?:

1. local?

2. active directory - if so, only via captive portal or another way?

....

thanks a lot!

Michael 

4 replies

ebilcari
Staff
Staff
June 28, 2024

You can find all possible configurations on this section of the guide. This feature is mostly used for devices (dummy), it can also be used for user groups or EMS tags but it's not that flexible to be considered a full NAC solution.

FortiNAC offers a complete NAC solution, you can read more about it here.

Emirjon
mrimmune
mrimmuneAuthor
New Member
June 29, 2024

Thanks a lot for response.

I know that FortiSwitch is not full NAC solution, but anyway it is unclear for me which users or users' group can be used in Fortiswitch NAC solution.

In one of articles I see usage AD users via captive portal.

Why do I need to use captive portal when Fortigate sees the username and IP of connecting device?

Thanks

Michael

ebilcari
Staff
Staff
July 1, 2024

I think that FGT will need an active authentication method in order to switch the VLAN on the port, so CP is required. Using a user group from a passive authentication method like FSSO may not be enough to identify the connected host.

Emirjon
Sheikh
Staff
Staff
June 30, 2024

Hello @mrimmune 

 

In order to apply user based NAC policies, please see this Article 

 

regards,

 

Sheikh

If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!