FortiNAC-F
FortiNAC-F is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks. For legacy FortiNAC articles prior to FortiNAC-F 7.2, see FortiNAC.
FortiElie
Staff
Staff
Article Id 393262
Description This article describes the procedure to manually update the Auto-Definition Directory for FortiNACs in Airgap environments, or when the FortiNAC cannot communicate with 'fnac-updates.fortinet.net'.
Scope FortiNAC, FortiNAC-F (all versions).
Solution

Usually, System Updates are configured under 'System -> Settings -> Updates -> System' to poll updates from 'fnac-updates.fortinet.net'. In this article, a local FTP repository will be used instead to poll these updates.

 

  1. Go to 'https://fnac-updates.fortinet.net/' from any browser. Credentials can be obtained from TAC support.
  2. Download the following files to a local machine:
    1. bnoui.txt.gz
    2. build-version.txt
    3. oui.txt.gz
    4. And the latest increment of the file which starts with 'AutoDefSynUpDates_*'. In this case, the file 'AutoDefSynUpDates_8.tar.gz' will be used.

 

Capture1.PNG

 

  1. Add these files to the root directory of the FTP server:

Capture2.PNG

   

  1. On the FortiNAC GUI, go to 'System -> Settings -> Updates -> System':
    1. Under 'Host:', provide the IP address of the FTP server.
    2. Under 'Auto-Definition Directory:', add '/'. This will correspond to the root directory of the FTP server.
    3. Under 'Product Distribution Directory:', add '/'.
    4. Under 'Agent Distribution Directory:', add '/'.
    5. Under 'User:', add the username of the FTP server.
    6. Under 'Password:', add the password of the FTP server.
    7. Under 'Protocol:', select 'FTP'.
    8. Select 'Test', and confirm that the FortiNAC can communicate with the FTP server.

 

Capture3.PNG

 

  1. Go to 'System -> Scheduler', select 'Auto-Definition Synchronizer', then select 'Run Now'.
  2. Go to 'Logs -> Events & Alarms -> Events' and confirm that the synchronization was successful.

 

Capture4.PNG

 

Notes:

Auto Definitions are updated periodically on 'https://fnac-updates.fortinet.net/', and this procedure should be done regularly by the FortiNAC administrator if the FortiNAC can't poll the updates automatically.

 

Related documents: