Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HeretoLearn23
New Contributor

Change Sponsor Email for Device Profile Rules

We have a Device Profile rule acting as our catch all for rogue devices. We have enabled 'Notify Sponsor'. This rule works and sends emails to a shared email account.

 

I need to change this email to something else and I can not seem to find this setting within 'Events & Alarms'.

Any help is appreciated 

 

NAC version 9.4.4.0767

 

Any help is appreciated 

Thank you

1 Solution
ebilcari
Staff
Staff

Basically this option (Notify Sponsor) will notify every user (in Administrators) with a valid email address that have the permission (Profiled Devices) enabled in their admin profile:

permissions.PNG

If Notify Sponsor is enabled, an email is sent by the FortiNAC server or Control server to all Device managers who have permission for devices associated with this rule. Permissions are based on the configuration of the administrator profile attached to the administrator.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

9 REPLIES 9
AEK
SuperUser
SuperUser

If it sends to an administrator called "user1" you need to edit that administrator and change its mail address, from menu Users & Hosts > Administrators.

AEK
AEK
ebilcari
Staff
Staff

Basically this option (Notify Sponsor) will notify every user (in Administrators) with a valid email address that have the permission (Profiled Devices) enabled in their admin profile:

permissions.PNG

If Notify Sponsor is enabled, an email is sent by the FortiNAC server or Control server to all Device managers who have permission for devices associated with this rule. Permissions are based on the configuration of the administrator profile attached to the administrator.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
HeretoLearn23

None of those options are checked for any of the profiles. 

We do have a generic user with the 'help desk' profile in the NAC, this user does have the disturbed group email added to it (this the email getting the alerts),

I just cant see how this ties into notify sponsor, like you describe above. 

 

AEK

If I in well your need, go to Logs > Events & Alarms > Mappings.

There you edit the mapping corresponding to your event and change the destination admin for mail notification.

AEK
AEK
HeretoLearn23

I thought this would be the case but we have not active mappings that I can tell tie into 'Notify Sponsor', granted I may be missing it. Here is the current mappings tied to a notification

2024_01_31_08_26_26_Window.png

ebilcari

If you want to do it through event mapping you can refer to this article, but in this case an email will be sent every time a new rouge is connected in the network, the desired DPR can't be selected.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
HeretoLearn23

Thank you for you help,  I narrowed it down to the Root admin

(which has this disturbed group email assigned to it), I changed that to my email and it sent to me only when a rogue connected. 

 

That being said I cant do the above changes you mentioned since it is a sys admin profile and doesn't have any modify options.  

 

Would it be best practice to remove the email from that local account(or assign a different one) and just follow your instructions and uses a different profile for this?

ebilcari

Yes, it won't cause any problems if you create a new user dedicated to this function and set the needed email address.

I agree that this feature should be a bit more granular in the first place but for the moment this are the available options.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ebilcari

Basically if the user that is part of Help Desk profile, has a valid email address and in this profile you check the boxes mentioned above this is considered a valid sponsor that get's notified when the DPR is hit by a host.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors