Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vincenzo
New Contributor II

Fnac mac address discovery filter

Hi Forticollegues,

I'm implementing a Fortinac solution to manage dynamic vlans via unique WiFi SSID.

The wifi networks and all wired networks are managed by Fortigate.

In Fnac inventory I see all Fortigates ports mapped and FNAC learn all client mac address from wired and wireless ports.

There is some methods to instruct the Fnac to learn mac address only by wireless networks? I don't need to manage all wired networks and I see a lot of rogue devices from Fortigate wired ports.

Thank you

Vincenzo

2 Solutions
scitlak

Hi,

 

Unfortunately, it is not possible to exclude a port or SSID in FortiNAC for L2 Polling. You may disable L2 polling for your FortiGate in FortiNAC but in this case, you will lose also visibility for WIFI clients.

 

View solution in original post

ebilcari
Staff
Staff

FNAC will try to find all connected hosts in the network devices it manages as long as they are present in their MAC address and ARP table. The case of the FGT is a bit unique since it manages both wired and WiFi hosts. Currently there is no way to filter the information and learn only the WiFi hosts.

The rogue devices will not consume any license. For better visibility, you can create a custom filter in Hosts/Adapters to show only Wireless hosts:

host filter.PNG

If the wired ports have a high turnover rate (new guest hosts daily), you can lower the aging time to a few days so the rouges are frequently cleaned up:

aging.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

5 REPLIES 5
AEK
SuperUser
SuperUser

Hi Enzo

One the three pillars of FortiNAC is visibility. If you remove it then you are like bling in your network and your FortiNAC is like useless.

AEK
AEK
vincenzo
New Contributor II

Hi Aek,

I don't wont remove Fnac, but in this case i don't need visibility of wired network. I collect a lot of rogue devices learned by wired net, but my single point of access is the SSID managed by Fortinac.

AEK

I mean if you remove visibility (even partially), not FNAC.

AEK
AEK
scitlak

Hi,

 

Unfortunately, it is not possible to exclude a port or SSID in FortiNAC for L2 Polling. You may disable L2 polling for your FortiGate in FortiNAC but in this case, you will lose also visibility for WIFI clients.

 

ebilcari
Staff
Staff

FNAC will try to find all connected hosts in the network devices it manages as long as they are present in their MAC address and ARP table. The case of the FGT is a bit unique since it manages both wired and WiFi hosts. Currently there is no way to filter the information and learn only the WiFi hosts.

The rogue devices will not consume any license. For better visibility, you can create a custom filter in Hosts/Adapters to show only Wireless hosts:

host filter.PNG

If the wired ports have a high turnover rate (new guest hosts daily), you can lower the aging time to a few days so the rouges are frequently cleaned up:

aging.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors