Created on
03-29-2023
11:46 PM
Edited on
03-10-2025
05:58 AM
By
Jean-Philippe_P
Description
This article describes the role assignment for FortiNAC users, hosts, and network devices. If more than one method is applied, the role selection will be chosen according to this list.
Scope
FortiNAC.
Solution
If multiple methods are used to set a role, the order of precedence is determined by the order of the roles on the Roles view
Starting from the top of the list, the first role match found is used.
Example.
If roles are assigned to hosts based on groups, the same host may be added to 2 groups after registration. For example, if the host is added to both 'Zebra_Handheld' and '-Local-User-GRP', the role assigned to the host will be the highest ranked role 'local-rad-role' associated with the '-Local-user-GRP'.
Figure 1. Arranging Role ranks with LDAP group membership.
Related documents:
Assigning roles - FortiNAC administration guide
Managing rules - FortiNAC administration guide
Technical Tip: How to populate a role from a group
Technical Tip: Assign Roles based on User LDAP Directory
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.