We have a Device Profile rule acting as our catch all for rogue devices. We have enabled 'Notify Sponsor'. This rule works and sends emails to a shared email account.
I need to change this email to something else and I can not seem to find this setting within 'Events & Alarms'.
Any help is appreciated
NAC version 9.4.4.0767
Any help is appreciated
Thank you
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Basically this option (Notify Sponsor) will notify every user (in Administrators) with a valid email address that have the permission (Profiled Devices) enabled in their admin profile:
If Notify Sponsor is enabled, an email is sent by the FortiNAC server or Control server to all Device managers who have permission for devices associated with this rule. Permissions are based on the configuration of the administrator profile attached to the administrator.
If it sends to an administrator called "user1" you need to edit that administrator and change its mail address, from menu Users & Hosts > Administrators.
Basically this option (Notify Sponsor) will notify every user (in Administrators) with a valid email address that have the permission (Profiled Devices) enabled in their admin profile:
If Notify Sponsor is enabled, an email is sent by the FortiNAC server or Control server to all Device managers who have permission for devices associated with this rule. Permissions are based on the configuration of the administrator profile attached to the administrator.
None of those options are checked for any of the profiles.
We do have a generic user with the 'help desk' profile in the NAC, this user does have the disturbed group email added to it (this the email getting the alerts),
I just cant see how this ties into notify sponsor, like you describe above.
If I in well your need, go to Logs > Events & Alarms > Mappings.
There you edit the mapping corresponding to your event and change the destination admin for mail notification.
I thought this would be the case but we have not active mappings that I can tell tie into 'Notify Sponsor', granted I may be missing it. Here is the current mappings tied to a notification
Created on 01-31-2024 06:45 AM Edited on 01-31-2024 06:45 AM
If you want to do it through event mapping you can refer to this article, but in this case an email will be sent every time a new rouge is connected in the network, the desired DPR can't be selected.
Thank you for you help, I narrowed it down to the Root admin
(which has this disturbed group email assigned to it), I changed that to my email and it sent to me only when a rogue connected.
That being said I cant do the above changes you mentioned since it is a sys admin profile and doesn't have any modify options.
Would it be best practice to remove the email from that local account(or assign a different one) and just follow your instructions and uses a different profile for this?
Created on 01-31-2024 07:38 AM Edited on 01-31-2024 07:38 AM
Yes, it won't cause any problems if you create a new user dedicated to this function and set the needed email address.
I agree that this feature should be a bit more granular in the first place but for the moment this are the available options.
Basically if the user that is part of Help Desk profile, has a valid email address and in this profile you check the boxes mentioned above this is considered a valid sponsor that get's notified when the DPR is hit by a host.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.