Skip to main content
Jannick
New Member
January 28, 2025
Question

Secure LAN port on FP231F using NAC

  • January 28, 2025
  • 2 replies
  • 672 views

Hi!

 

Recently we started a little PoC for a new project. On the project we're looking to implement a FortiGate-100E, a FortiSwitch 224E-POE and FortiAPs (we're now testing with the FP231F, but might choose other models).

 

Our goal is to have in every room an AP with 3 outgoing ports. 2 ports are for fixed devices and 1 port is for a BYOD device.

 

In our current config we're looking to use NAC. It's a powerful method and we got it fully working for wireless devices connecting to different SSIDs. The only thing we're running into right now is applying NAC to the LAN port(s) on the FortiAP.

 

By putting the FP231F into WAN-LAN modus and bridiging the LAN port to a hidden SSID configured to a specific VLAN (13), we managed to put wired connections into the LAN2 port on VLAN 13 (without NAC enabled). When enabeling NAC for the SSID, the device goes into the VLAN the AP is one while the NAC policy states it should go into VLAN 13 (in this specific case). It seems like NAC is completly not working/ignored for the wired device.

 

My question is: Is it possible to use NAC on one or more LAN ports of a FortiAP? If so, how? If not, what method would you apply to have a LAN port fully secured to a single device (like NAC with MAC, Vendor and more).

 

Thank you!

2 replies

ebilcari
Staff
Staff
January 28, 2025

Can you specify if this request is for NAC Policies in FGT or FortiNAC as a dedicated NAC product/solution?

Emirjon
Jannick
JannickAuthor
New Member
January 28, 2025

My request is specifically about the NAC Policies in FGT.