Description
A rogue connected to the network matches the wrong Device Profiling Rule:
- If matching rule is configured for automatic registration, the host is registered as the wrong device.
- If matching rule is configured for manual registration, the host remains rogue and is listed under Profiled Devices in the Administration UI with the wrong matching rule name.
Scope
Version: FortiNAC v9.x, FortiNAC-F 7.x.
Solution
- In the Administration UI, navigate to Users & Hosts -> Device Profiling Rules.
- Review the following:
- Ensure the desired rule is enabled.
- Rule ranking - Is the matching rule ranked above the desired rule to be matched? For ranking best practices, refer to the Device Profiler document in Fortinet Document Library.
- Rule methods - Verify the host is not missing any required criteria in order to match the desired profiling rule.
- After making corrections, test the rogue against the desired rule. Search for the MAC address in Users & Hosts -> Adapters.
- Right-click on the adapter record and select Test Device Profiling Rule.
- Once the rule matches, re-run the rogue host evaluation. Go to Users & Hosts -> Device Profiling Rules and select Run.
Related documents:
Technical Tip: Troubleshooting rogue not matching any device profiles
Device Profiling Configuration Reference Manual