Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mbas
New Contributor

Creating Contractor user with a corporate email address causing existing user isolation

Dear team,

 

Has anyone else observed this issue?

 

When we create a contractor user with a corporate email address and no one logs in with that user, after a while, it causes the existing user VLAN to change to isolation. When I check that user and click Show Hosts, I can see another host belonging to the same user with the contractor email address. The strange thing is that when I check that host, I can see that the logged-on user is the contractor user, even though we did not log in.

 

Somehow, I guess the passive agent finds that device user, checks the email address, and matches it with the contractor user. Is this normal behavior? It's not happening instantly; it takes some time to detect the other host and link it with the contractor user.

 

My goal is to create a contractor user, assign them to the onboarding VLAN, and install new computers. That's why the help desk team creates users with corporate email addresses and keeps them for a month. Do you have any suggestions for overcoming this issue?

Solving a problem is the best feeling.
Solving a problem is the best feeling.
6 REPLIES 6
AEK
SuperUser
SuperUser

Hi mbas

I may not have understood the issue you described but I think I understand your requirement.

You want to assign the new hosts of your company that are not yet part of the domain to a special VLAN where the helpdesk team can install it and join it to the domain, right?

AEK
AEK
mbas
New Contributor

Yes, this is the requirement. I want to use the contractor template for this. This way, all help desk personnel can create a user account for themselves and log in with a new computer, and I can assign them an onboarding VLAN.

 

However, if another device has the same email as the contractor user, FortiNAC links that device to the contractor user, which I don't want to happen. I enabled Passive Agent for user tracking, but I think because of that, FortiNAC finds all devices related to that email address and shows the contractor user as the logged-on user.

I did not expect to see the logged-on user be the contractor user on an existing computer. That's where I got confused :)

Solving a problem is the best feeling.
Solving a problem is the best feeling.
AEK

So why should it be a contractor account? Why not AD account?

Once he gets the portal, the helpdesk will login with his AD account and he will be dropped in the special VLAN.

And once the PC joins the domain and persistent agent is installed the policy will drops it in the prod VLAN.

Is there any problem with this scenario?

AEK
AEK
mbas
New Contributor

 

In that scenario, each device will be registered under the same Help Desk username. In the Host menu, we don't want to see every host registered to the same help desk user. However, in this case, we can delete the host from FortiNAC once installation is complete. The main concern is that the customer does not want to grant permission to help desk users. They also don't want to enable user login with AD credentials because otherwise, everyone will register their different devices.

 


I cannot enable user login without a separate portal. I also cannot differentiate users, that is why I cannot use a portal policy. How can I create user profiles for guest and onboarding users? Any suggestions?

Solving a problem is the best feeling.
Solving a problem is the best feeling.
ebilcari

You can also check if the 'Game Console' option help meet this requirement, some information can be found here.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ebilcari
Staff
Staff

Is the contractor username related to the user part of the email address that is used? Does these host have the Persistent Agent installed while they are onboarding? 

FNAC will try to match Users after they successfully register a host and by default will try to cut the domain part and just match the sAMAccountName.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors