Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ByteHaven
New Contributor II

Device profiling rule

Hello FNAC admins,

What's the most recommended method(s) in device profiling rules ? I know it depends for each scenario. 

Also I wanna know if it's best to use many methods in one rule, or each rule better have one method ?

 

Thanks in advance

BR,

2 Solutions
AEK
SuperUser
SuperUser

Hello BH

All I remember is that lighter rules should be at top. This helps FNAC to profile devices without using much resources.

Have a look at the best practices:

https://docs.fortinet.com/document/fortinac-f/7.6.0/administration-guide/185068/best-practices

 

Besides, if you need it more secure in device auto registration or re-validation then then "I think" you may need to harden the profiling rules instead of using OUI, DHCP fingerprint and other weak methods.

Hope it helps.

 
AEK

View solution in original post

AEK
ebilcari
Staff
Staff

The details are covered on this dedicated guide Device Profiler Configuration, and Prioritization is very important. Rules should be ordered accordingly, and any rules that include methods from 'Must Be Received' should always be placed at the bottom.
For example, if a host matches a rule that evaluates DHCP but lacks DHCP fingerprint details, its evaluation becomes stuck, and other rules are not processed.
Methods under 'Needs to Be Read' usually require a host IP to extract information. Ensure that FNAC can receive this information through L3 polling on network devices.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

4 REPLIES 4
AEK
SuperUser
SuperUser

Hello BH

All I remember is that lighter rules should be at top. This helps FNAC to profile devices without using much resources.

Have a look at the best practices:

https://docs.fortinet.com/document/fortinac-f/7.6.0/administration-guide/185068/best-practices

 

Besides, if you need it more secure in device auto registration or re-validation then then "I think" you may need to harden the profiling rules instead of using OUI, DHCP fingerprint and other weak methods.

Hope it helps.

 
AEK
AEK
ByteHaven
New Contributor II

Thank you for the help AEK, I understand now

 

BR,

ebilcari
Staff
Staff

The details are covered on this dedicated guide Device Profiler Configuration, and Prioritization is very important. Rules should be ordered accordingly, and any rules that include methods from 'Must Be Received' should always be placed at the bottom.
For example, if a host matches a rule that evaluates DHCP but lacks DHCP fingerprint details, its evaluation becomes stuck, and other rules are not processed.
Methods under 'Needs to Be Read' usually require a host IP to extract information. Ensure that FNAC can receive this information through L3 polling on network devices.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ByteHaven
New Contributor II

Thank you for this detailed explanation Emirjon. I will defo read those articles after that I am done with the admin guide

 

BR,

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors