Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @unknown1020
As per admin guide, Rogues are those devices that do not match any of the rules enabled in the device profiling rules. You may also have hosts that have been categorized incorrectly.
So if you have such hosts then please check EPC policies and other relevant Policies e.g. Network Access policies.
You can also right click the host and check Policy Details anf then check EPC Policies status.
regards,
Sheikh
The definition of rouge in FNAC is a physical address that has been seen on the network but has not been associated with an existing known host and is therefore considered unknown. There are several ways to register hosts like Device profiling, through web portal, dot1x auto registration through RADIUS information, manual registration, import etc.
In the Endpoint Fingerprints menu you may find all the MAC addresses learned by FNAC and the source of that information. Same MAC address can also be shown multiple times to keep it as a reference when the source is different. There is also the "Set Source Rank" option that shows which Source is considered more "trustworthy" than can override the information.
Rogue are the device that do not communicate with the fortinac or the unregistered device? Since the report indicates "last communication"
Every host/device need to communicate with FNAC even when they are isolated through FNAC's isolation interface for different reasons:
Rouge - will have to be classified (active mode)
At-Risk - need to be remediated and update their compliance status
Authentication - user need to authenticate
Dead-end - (optional) only to show the portal and notify the end host
In Fortinac, is it possible to generate a report with the exclusions that have been made on the device in the fortinac?
The built-in reports are a bit limited now in FNAC since the FNAC Analytics Reporting got discontinued in 2019, now FortiAnalyzer is needed for generating reports. More info can be found on this section of Administration Guide. Current built in reports are:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.