FortiOS 5.0.9
I am having issues getting specific forticlient profiles pushed to named devices that have been assigned to device groups. The following is my analysis of the issue and identifies what I believe to be a bug:
When a client (Forticlient 5.0.9) registers to the Fortigate (5.0.9), it identifies all of the clients mac addresses (i.e. lan mac, wireless mac, fortiiclient vpn mac, etc..). By way of example the following is the output of a mouse-over of my laptop on the Device Definitions page. Note that four macs are identified.
Device PA0042449-mayer
Primary MACe4:11:5b:2b:a3:2f (port1)
MAC Addresscc:52:af:ec:5e:23 ()
MAC Address10:0b:a9:1b:4e:d4 ()
MAC Address10:0b:a9:1b:4e:d5 ()
OSWindows / 7 Service Pack 1
HostnamePA0042449
DomainGOVSOLUTIONS.COM
Usernamemayer
IP Address135.22.254.39
Last Seen12:00:56 (port1)
FortiClient State Registered
In order to add the device to a device group and thereby be able to push a specific forticlient profile to it, I need to make the device permanent (i.e. give it an alias).
When I make that device entry permanent - by double-clicking its entry and giving it an alias, only one of its mac address become associated with the name/alias. By way of example, I made the above entry permanent giving it the name ' PA0042449-mayer" .
When viewed through the Fortigate GUI, the name/alias appears to be associated with all 4 macs. Here is the new Device Definition mouse-over output:
Device PA0042449-mayer
Primary MAC10:0b:a9:1b:4e:d5 (port1)
MAC Addresscc:52:af:ec:5e:23 ()
MAC Addresse4:11:5b:2b:a3:2f ()
MAC Address10:0b:a9:1b:4e:d4 ()
OSWindows / 7 Service Pack 1
HostnamePA0042449
Usernamemayer
IP Address135.22.255.40
Last Seen13:43:08 (port1)
But viewed through the CLI, the name/alias appears to only be associated with one macaddress.:
fgfct-01 # config user device
fgfct-01 (device) # edit PA0042449-mayer
fgfct-01 (PA0042449-mayer) # show
config user device
edit " PA0042449-mayer"
set mac e4:11:5b:2b:a3:2f
set type windows-pc
next
end
The result - and the issue I am trying to define - is that when I add that named device to a device group, the associated forticlient profile is only pushed when the laptop is connected via the one MAC shown in the Config User Device entry. If the laptop connects via another mac address - say wireless or vpn, the the laptop gets the " default" profile.
So for Fortigate GUI Device Definition display purposes, the assigned name/alias is associated with all of the device' s mac addresses. But for the purposes of device group membership and forticlient profile pushes, then device name/alias is only associated with a single address.
Am I doing something wrong or is this a bug?
Rich Mayer
LGS Innovations
Rich Mayer
LGS Innovations