Hello, I was digging into creating NAC policies using user-based policies. Currently, I am using FSSO user groups in the user group attribute.
I did create a firewall policy to allow traffic between the onboarding VLAN and the collector agent server, and the user is authenticated without hitting the NAC policy. I am wondering if I can use FSSO user groups in NAC policies. Any ideas?
@liliin wrote:Hello, I was digging into creating NAC policies using user-based policies. Currently, I am using FSSO user groups in the user group attribute. mobile tyre fitting Manchester
I did create a firewall policy to allow traffic between the onboarding VLAN and the collector agent server, and the user is authenticated without hitting the NAC policy. I am wondering if I can use FSSO user groups in NAC policies. Any ideas?
Yes, FSSO user groups can be used in NAC policies, but there are some important considerations. NAC policies typically evaluate unauthenticated devices first, so if your user is already authenticated via FSSO (especially through a firewall policy), the NAC policy might be bypassed. To ensure NAC policies are triggered, you may need to adjust the policy order or authentication flow so that the NAC policy is evaluated before full user authentication takes place.
Thank you for sharing the details. Could you please illustrate the correct rule order to ensure NAC policy authentication is applied first?
I attempted this setup, but the user remains stuck in the onboarding VLAN, and I see no hits on the NAC policy.
The order I currently use is:
Firewall rule from the onboarding VLAN to AD.
Firewall rule from the onboarding VLAN to the Internet.
User | Count |
---|---|
2570 | |
1362 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.