Created on
03-31-2024
11:01 PM
Edited on
04-09-2025
01:21 AM
By
Jean-Philippe_P
Description |
This article is a setup assistance that can be used on one workstation to change network access policies based on a logged-on user. |
Scope | FortiNAC. |
Solution |
If a host is being used with different logged-on users and a different network access policy is desired, review the following.
Example: Upon importing LDAP groups, handle groups by placing them into 'Type: Host' because they are tied to a host. FortiNAC does not have a direct way to associate the host with a user, so it is possible to create roles to accomplish this association
Registered to the user ID of the user to which this host is registered: Settings.
Who/What By Group 'Host or User groups where the host or user must be a member to match this profile: User/host profiles.
However, because the host is tied to the original user1 LDAP group. It will be necessary to add a condition to the Who/What in the user tab. For example: user1 is part of role FNAC_LAB. The role per logged-on user is dynamic and follows the user vs the host role will be tied to the user in which the host was registered review the host record below:
User 1:
User 2:
Host record: Notice the host is tied to the owner of user1 and its role.
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.