FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 191828

Description


This article describes how to identify and disable traps for uplink ports in switch configurations. Although traps for uplinks are not acted upon, they cause extra work for the appliance, as FortiNAC processes each trap received.

 

Scope

 

FortiNAC, FortiNAC-F  .


Solution

 

How to Identify devices sending traps from uplink ports:
 
  1. Enable the relevant event:
  1. In Administrative GUI, navigate to Logs -> Event&Alarms ->Management.
  2. 'Right-click' on the event Mac Change on Uplink and select Internal.

Figure 1. Enable Logging for the "MAC change event on uplink" event.Figure 1. Enable Logging for the "MAC change event on uplink" event.

 

  1. Identify uplink ports sending MAC Notification traps:
  1. Navigate to Logs -> Events.
  2. Add Filter: Event
  3. From the Event drop-down, select Mac Change on Uplink.
  4. Adjust the Date filter as appropriate.
  5. Select Update.
  6. To export results to a spreadsheet, select the icon for the type of export file needed at the bottom of the window (such as Excel).
  7. Select 'OK'.

 

Figure 2. Filter for learned events in the last 1 hour.Figure 2. Filter for learned events in the last 1 hour.

 

  1. After finishing with device identification, disable the event.  Otherwise, the event archive files could get unnecessarily large:
  • Go to Logs -> Event Management.
  • 'Right-click' on the event Mac Change on Uplink and select Disabled.

 

Related documents:

Port uplink types

Configuring Traps for MAC Notification

Learning about hosts on the network

Technical Tip: Performance issue and some general recommendations