Dear team,
Has anyone else observed this issue?
When we create a contractor user with a corporate email address and no one logs in with that user, after a while, it causes the existing user VLAN to change to isolation. When I check that user and click Show Hosts, I can see another host belonging to the same user with the contractor email address. The strange thing is that when I check that host, I can see that the logged-on user is the contractor user, even though we did not log in.
Somehow, I guess the passive agent finds that device user, checks the email address, and matches it with the contractor user. Is this normal behavior? It's not happening instantly; it takes some time to detect the other host and link it with the contractor user.
My goal is to create a contractor user, assign them to the onboarding VLAN, and install new computers. That's why the help desk team creates users with corporate email addresses and keeps them for a month. Do you have any suggestions for overcoming this issue?
Hi mbas
I may not have understood the issue you described but I think I understand your requirement.
You want to assign the new hosts of your company that are not yet part of the domain to a special VLAN where the helpdesk team can install it and join it to the domain, right?
Yes, this is the requirement. I want to use the contractor template for this. This way, all help desk personnel can create a user account for themselves and log in with a new computer, and I can assign them an onboarding VLAN.
However, if another device has the same email as the contractor user, FortiNAC links that device to the contractor user, which I don't want to happen. I enabled Passive Agent for user tracking, but I think because of that, FortiNAC finds all devices related to that email address and shows the contractor user as the logged-on user.
I did not expect to see the logged-on user be the contractor user on an existing computer. That's where I got confused :)
So why should it be a contractor account? Why not AD account?
Once he gets the portal, the helpdesk will login with his AD account and he will be dropped in the special VLAN.
And once the PC joins the domain and persistent agent is installed the policy will drops it in the prod VLAN.
Is there any problem with this scenario?
In that scenario, each device will be registered under the same Help Desk username. In the Host menu, we don't want to see every host registered to the same help desk user. However, in this case, we can delete the host from FortiNAC once installation is complete. The main concern is that the customer does not want to grant permission to help desk users. They also don't want to enable user login with AD credentials because otherwise, everyone will register their different devices.
I cannot enable user login without a separate portal. I also cannot differentiate users, that is why I cannot use a portal policy. How can I create user profiles for guest and onboarding users? Any suggestions?
You can also check if the 'Game Console' option help meet this requirement, some information can be found here.
Yes, that's another option, but it doesn't limit access. Anyone can register that way. What I will do is create a local user for the help desk. If an 802.1x request comes in with that local user, I will put it into the onboarding VLAN. Then, I will remove the host from the FNAC.
Is the contractor username related to the user part of the email address that is used? Does these host have the Persistent Agent installed while they are onboarding?
FNAC will try to match Users after they successfully register a host and by default will try to cut the domain part and just match the sAMAccountName.
The new user does not have PA, but the existing user does. We just created a contractor account, and even without logging in, the existing user was isolated after 5-10 minutes. The contractor username and the existing user have the same email address.
If FNAC is matching, then I will tell them not to create any contractor accounts with the same email addresses as existing users.
The only thing I don't understand is why the FNAC changed the logged-on user to the contractor user on the existing host.
Thanks, Emirjon.
| User | Count |
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.