Description |
These articles identify why Flex CLI configurations are not being applied in port-based configurations via Device model configuration. |
Scope | FortiNAC-F, FortiNAC |
Solution |
FortiNAC can apply 1.Port Based Configurations and 1. Host Based Configurations to enforce control on endpoints connected to modeled devices.
Related document: Apply a port based configuration via model configuration
Related document: Apply a host based configuration via the model configuration
When applying CLI configurations via the device model, FortiNAC will need to bind the CLI configuration to the Device itself. It then applies and removes the CLI configuration based on the Control states explained in this article. A common misconfiguration is to leave the control states without the specific CLI configuration. FortiNAC in this case will not use it even if there is a logical network with the Access VLAN and CLI configuration defined. At least one Control/Isolation state should have the CLI configuration defined even if set to 'deny'. This way FortiNAC will associate the CLI configuration to the Device.
Example: In this case there is a CLI configuration called 'test'. Either by selecting 'In Use' or by editing the CLI configuration in Network -> CLI Configuration it is possible to detect if it is currently in use or not.
At this point, any host that would match a Network Access Policy that has the 'test' CLI configuration enabled would not have it applied. This happens because FortiNAC has no Inventory device listed that uses this configuration. Checking the model configuration of the Cisco Device it is possible to verify that all controll states have no CLI configuration defined.
At least one of the four control states should have the 'test' CLI configuration enabled even if the Access Enforcement is set to 'Deny'. After setting the CLI configuration to one of the control states and selecting 'save', verify again the Usage of the 'test' configuration.
This shows that any host connecting to Devices where the CLI configuration is in use, will have it applied depending on the Network access configuration The following verifications need to be made in order for the Port based configuration to be applied:
Options for Flex CLI configuration:
Related documents: Technical Note: Configuring Flex CLI with Network Device Roles |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.