Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rsmayer
New Contributor

Endpoint Control/Device Groups: FGT only pushes custom FCT config to client when using " Primary" mac

FortiOS 5.0.9 I am having issues getting specific forticlient profiles pushed to named devices that have been assigned to device groups. The following is my analysis of the issue and identifies what I believe to be a bug: When a client (Forticlient 5.0.9) registers to the Fortigate (5.0.9), it identifies all of the clients mac addresses (i.e. lan mac, wireless mac, fortiiclient vpn mac, etc..). By way of example the following is the output of a mouse-over of my laptop on the Device Definitions page. Note that four macs are identified. Device PA0042449-mayer Primary MACe4:11:5b:2b:a3:2f (port1) MAC Addresscc:52:af:ec:5e:23 () MAC Address10:0b:a9:1b:4e:d4 () MAC Address10:0b:a9:1b:4e:d5 () OSWindows / 7 Service Pack 1 HostnamePA0042449 DomainGOVSOLUTIONS.COM Usernamemayer IP Address135.22.254.39 Last Seen12:00:56 (port1) FortiClient State Registered In order to add the device to a device group and thereby be able to push a specific forticlient profile to it, I need to make the device permanent (i.e. give it an alias). When I make that device entry permanent - by double-clicking its entry and giving it an alias, only one of its mac address become associated with the name/alias. By way of example, I made the above entry permanent giving it the name ' PA0042449-mayer" . When viewed through the Fortigate GUI, the name/alias appears to be associated with all 4 macs. Here is the new Device Definition mouse-over output: Device PA0042449-mayer Primary MAC10:0b:a9:1b:4e:d5 (port1) MAC Addresscc:52:af:ec:5e:23 () MAC Addresse4:11:5b:2b:a3:2f () MAC Address10:0b:a9:1b:4e:d4 () OSWindows / 7 Service Pack 1 HostnamePA0042449 Usernamemayer IP Address135.22.255.40 Last Seen13:43:08 (port1) But viewed through the CLI, the name/alias appears to only be associated with one macaddress.: fgfct-01 # config user device fgfct-01 (device) # edit PA0042449-mayer fgfct-01 (PA0042449-mayer) # show config user device edit " PA0042449-mayer" set mac e4:11:5b:2b:a3:2f set type windows-pc next end The result - and the issue I am trying to define - is that when I add that named device to a device group, the associated forticlient profile is only pushed when the laptop is connected via the one MAC shown in the Config User Device entry. If the laptop connects via another mac address - say wireless or vpn, the the laptop gets the " default" profile. So for Fortigate GUI Device Definition display purposes, the assigned name/alias is associated with all of the device' s mac addresses. But for the purposes of device group membership and forticlient profile pushes, then device name/alias is only associated with a single address. Am I doing something wrong or is this a bug? Rich Mayer LGS Innovations
Rich Mayer LGS Innovations
Rich Mayer LGS Innovations
1 REPLY 1
rwdorman
New Contributor III

Had this exact same issue and opened a TAC ticket, they are calling it an identified bug. The work around for me for the moment was to use username rather than MAC. Its no ideal but it got me pas where i needed. I' m assuming you' re on 5.2?

-rd 2x 200D Clusters 1x 100D

1x 60D FortiOS 5.2 FortiAP 221C FAZ 200D

-rd 2x 200D Clusters 1x 100D 1x 60D FortiOS 5.2 FortiAP 221C FAZ 200D
Labels
Top Kudoed Authors