Skip to main content
doncacciatoconsuting
Explorer II
August 16, 2024
Question

Manual switchport/SSID changes when using FortiNAC

  • August 16, 2024
  • 2 replies
  • 910 views

Let's say I have a switch/AP that is being managed by a platform like FortiManager or Mist (Juniper). If changes are made with these tools, I'm assuming that:

- NAC will poll the switch/AP as usual and get the new parameters like VLAN ID, etc. 

- Run policies as usual and make changes to switchports accordingly.

 

 

Is this correct ? 

 

Any best practices for NAC when using such management tools ?

Don 

2 replies

AEK
SuperUser
SuperUser
August 17, 2024

As per my knowledge FortiManager manages FortiSwitches and FortiAPs only if they are managed by FortiGate.

  • In that case, NAC will pol FortiGate to read the switch port status, VLAN ID and so, it will not poll the AP and switch directly, but through FGT
  • NAC runs policies as usual and make changes to switch-ports and AP through FortiGate, not directly

FortiNAC also manages standalone FortiSwitch.

Check the below docs for both cases.

https://docs.fortinet.com/document/fortinac-f/7.2.0/fortiswitch-fortilink-integration-guide/365563/overview

https://docs.fortinet.com/document/fortinac-f/7.2.0/fortiswitch-standalone-integration-guide/222669/overview

Hope it helps.

AEK
ebilcari
Staff
Staff
August 19, 2024

Technically, each time a device configuration is done outside of FNAC, a manual 'Resync Interfaces' need to be performed (it can also be scheduled like shown here). Depending on the type and the frequency of the configuration changes done externally, it may have undesired results for the integration with FNAC.

I would suggest to use RADIUS and dynamic VLAN assignments in order to not relay on configuration changes for changing VLANs or enforce policies.

Emirjon
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!