FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiElie
Staff
Staff
Article Id 372848
Description This article describes how to configure user acknowledgement for VLAN Switching with Persistent Agent so the user can accept or deny changing the VLAN.
Scope

FortiNAC-F 7.4, 7.6.

Persistent Agent 9.4.4 or 10.7.2 or greater.

Solution

In some environments it might be required to get user acknowledgment before switching their VLAN. The user would get a notification similar to the following:

 

PA_vlan_change_acknowledgement.PNG

 

First make sure the Persistent Agent is installed on the host and can communicate with the FortiNAC. Go to 'Users & Hosts -> Hosts' and look for the green checkmark under the 'Persistent Agent' column:

 

PA_communicating.png

 

Enable the 'Enable VlanSwitching User Acknowledgement' option under 'System -> Settings -> Persistent Agent -> Properties':

 

user_acknowledgement.png


To enable it from CLI:

 

execute enter-shell

globaloptiontool -name persistentAgentSecMgmt.enableReceipt -set true

 

To disable it from the CLI:

 

execute enter-shell

globaloptiontool -name persistentAgentSecMgmt.enableReceipt -set false

 

Note:

If the user does not select any option, the VLAN will be switched after the time defined under the 'Acknowledgement timeout' field.

 

Related documents:

Properties - FortiNAC-F administration guide

Persistent agent deployment and configuration overview - FortiNAC-F administration guide

Technical Tip: Troubleshooting the Persistent agent