FortiNAC-F
FortiNAC-F is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks. For legacy FortiNAC articles prior to FortiNAC-F 7.2, see FortiNAC.
Hatibi
Staff
Staff
Article Id 343818
Description This articles describes the Host Inventory portal page configuration and end user experience when managing their registered devices.
Scope FortiNAC-F, FortiNAC.
Solution

The Host Inventory is a success page that allows end users to manage their registered devices without administrator interventions.

This is helpful in cases where FortiNAC limits the number of devices per user and allows the user to manage their own devices.

Once the limit of devices is reached, the users will be presented a notification message in the portal.

 

To enable the Host Inventory go to Portal -> Portal Configuration -> Global -> Settings. Under the drop-down button in Success Page Type select 'Host Inventory. 

 

Figure 1. Enable 'Host Inventory' success page in Global settings.Figure 1. Enable 'Host Inventory' success page in Global settings.

 

 

The settings for the Host Inventory page can be defined in Portal -> Portal Configuration -> Host Inventory -> Controls.

Figure 2. Host Inventory Controls settings.Figure 2. Host Inventory Controls settings.

 

 

 

Once the required features are configured and the portal configuration is saved, the users will be able to check their Host inventory in the: https://<IP or hostname of FortiNAC appliance>/registration/DeviceInventory.jsp

 

Additionally, if users register devices through the portal they will be redirected to the Host Inventory success page.

 

Examples of Notification messages on the Host Inventory page.

 

  1. InvalidMAC: When attempting to register the host the user is prompted the failure to register the device as shown in Figure 3.

 

Figure 3. Invalid MAC address means the Vendor OUI is not present in FortiNAC database.Figure 3. Invalid MAC address means the Vendor OUI is not present in FortiNAC database.

 

Cause: The message appears due to FortiNAC not having the Vendor OUI of the given MAC address in its Database:Technical Tip: 'Invalid Physical Address' error in event logs preventing host registration

 

  1. Unable to Locate the Host: When attempting to register the host the user is prompted the message as shown in Figure 4. FortiNAC shows an offline record of the host in Host View. 

 

Figure 4. FortiNAC is unable to locate host and reports it as offline in Host View.Figure 4. FortiNAC is unable to locate host and reports it as offline in Host View.

 

Cause: FortiNAC is unable to learn the endpoint due to L2/L3 polling issues or being unable to parse port information from the response it gets from the device where the host is connected. 

 

Related articles:

Troubleshooting Tip: Troubleshooting CLI credential failure

Technical Tip: Troubleshooting SNMP communication issues

 

  1. Host Limit Reached: When the user tries to register the device the following message as per Figure 5 is shown.

 

Figure 5. The user has reached the maximum number of allowed hosts.Figure 5. The user has reached the maximum number of allowed hosts.

 

Cause: The limit of 1/1 hosts has been reached.  The output.master will log the following message:

 

yams INFO :: 2024-09-25 11:01:15:181 :: #6414 ::Registration FAILED srogers Host Over Registered Physical Address Limit srogers

 

The user cannot register any new devices and will need to delete an already registered device to register a new one.

The number of allowed hosts is defined in System -> Settings -> User/Host Management -> Allowed Hosts

 

Related documents:

Host Inventory

Technical Tip: FortiNAC Guest Captive Portal configuration and workflow

Technical Tip: Captive Portal is not showing for Rogue Hosts

Troubleshooting Tip: FortiNAC fails to move rogue switches to registration VLAN