Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
liliin
New Contributor

Built in NAC policy

Hello, I was digging into creating NAC policies using user-based policies. Currently, I am using FSSO user groups in the user group attribute.

I did create a firewall policy to allow traffic between the onboarding VLAN and the collector agent server, and the user is authenticated without hitting the NAC policy. I am wondering if I can use FSSO user groups in NAC policies. Any ideas?

omegle xender
2 REPLIES 2
jimmi
New Contributor


@liliin  wrote:

Hello, I was digging into creating NAC policies using user-based policies. Currently, I am using FSSO user groups in the user group attribute. mobile tyre fitting Manchester

I did create a firewall policy to allow traffic between the onboarding VLAN and the collector agent server, and the user is authenticated without hitting the NAC policy. I am wondering if I can use FSSO user groups in NAC policies. Any ideas?


Yes, FSSO user groups can be used in NAC policies, but there are some important considerations. NAC policies typically evaluate unauthenticated devices first, so if your user is already authenticated via FSSO (especially through a firewall policy), the NAC policy might be bypassed. To ensure NAC policies are triggered, you may need to adjust the policy order or authentication flow so that the NAC policy is evaluated before full user authentication takes place.

 
 
BIRO
New Contributor

Thank you for sharing the details. Could you please illustrate the correct rule order to ensure NAC policy authentication is applied first?

I attempted this setup, but the user remains stuck in the onboarding VLAN, and I see no hits on the NAC policy.

The order I currently use is:

  1. Firewall rule from the onboarding VLAN to AD.

  2. Firewall rule from the onboarding VLAN to the Internet.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors