Hello, I was digging into creating NAC policies using user-based policies. Currently, I am using FSSO user groups in the user group attribute.
I did create a firewall policy to allow traffic between the onboarding VLAN and the collector agent server, and the user is authenticated without hitting the NAC policy. I am wondering if I can use FSSO user groups in NAC policies. Any ideas?
Thank you for sharing the details. Could you please illustrate the correct rule order to ensure NAC policy authentication is applied first?
I attempted this setup, but the user remains stuck in the onboarding VLAN, and I see no hits on the NAC policy.
The order I currently use is:
Firewall rule from the onboarding VLAN to AD.
Firewall rule from the onboarding VLAN to the Internet.
| User | Count |
|---|---|
| 2695 | |
| 1412 | |
| 810 | |
| 713 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.