FortiNAC-F
FortiNAC-F is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks. For legacy FortiNAC articles prior to FortiNAC-F 7.2, see FortiNAC.
scitlak
Staff
Staff
Article Id 417760
Description This article describes how to assign a host role using the FortiNAC Persistent Agent auto-registration feature.
Scope FortiNAC, FortiNAC -F.
Solution

Since FortiNAC Persistent Agent auto-registration does not natively provide an option to assign roles, it is commonly observed that Device Profiling Rules are used when role assignment is required. Although this option is not available natively, it is possible to assign roles to hosts by following the steps outlined below using FortiNAC Persistent Agent auto-registration.

 

  1. Configure the FortiNAC Persistent Agent Credential Configuration as shown below.

 

04.11.2025_12.58.20_REC.png

 

  1. Create a local host group as shown below.

 

04.11.2025_12.58.01_REC.png

 

  1. Create a Passive Agent rule, and under 'Add to Groups', select the host group that was created in the previous step. 

 

04.11.2025_12.58.42_REC.png

 

  1. Create a role and add the host group created in the second step into this role, as shown below.

 

04.11.2025_12.56.24_REC.png

 

  1. When a rogue host establishes a Persistent Agent connection, it will be registered through the Passive Agent rule. Since the host group is selected in the Passive Agent rule, the host will be added to that group. As the same group is also associated with the created role, the host will automatically be assigned the desired role.

 

04.11.2025_12.55.51_REC.png