Hi Forticollegues,
I'm implementing a Fortinac solution to manage dynamic vlans via unique WiFi SSID.
The wifi networks and all wired networks are managed by Fortigate.
In Fnac inventory I see all Fortigates ports mapped and FNAC learn all client mac address from wired and wireless ports.
There is some methods to instruct the Fnac to learn mac address only by wireless networks? I don't need to manage all wired networks and I see a lot of rogue devices from Fortigate wired ports.
Thank you
Vincenzo
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Unfortunately, it is not possible to exclude a port or SSID in FortiNAC for L2 Polling. You may disable L2 polling for your FortiGate in FortiNAC but in this case, you will lose also visibility for WIFI clients.
FNAC will try to find all connected hosts in the network devices it manages as long as they are present in their MAC address and ARP table. The case of the FGT is a bit unique since it manages both wired and WiFi hosts. Currently there is no way to filter the information and learn only the WiFi hosts.
The rogue devices will not consume any license. For better visibility, you can create a custom filter in Hosts/Adapters to show only Wireless hosts:
If the wired ports have a high turnover rate (new guest hosts daily), you can lower the aging time to a few days so the rouges are frequently cleaned up:
Hi Enzo
One the three pillars of FortiNAC is visibility. If you remove it then you are like bling in your network and your FortiNAC is like useless.
Hi Aek,
I don't wont remove Fnac, but in this case i don't need visibility of wired network. I collect a lot of rogue devices learned by wired net, but my single point of access is the SSID managed by Fortinac.
I mean if you remove visibility (even partially), not FNAC.
Hi,
Unfortunately, it is not possible to exclude a port or SSID in FortiNAC for L2 Polling. You may disable L2 polling for your FortiGate in FortiNAC but in this case, you will lose also visibility for WIFI clients.
FNAC will try to find all connected hosts in the network devices it manages as long as they are present in their MAC address and ARP table. The case of the FGT is a bit unique since it manages both wired and WiFi hosts. Currently there is no way to filter the information and learn only the WiFi hosts.
The rogue devices will not consume any license. For better visibility, you can create a custom filter in Hosts/Adapters to show only Wireless hosts:
If the wired ports have a high turnover rate (new guest hosts daily), you can lower the aging time to a few days so the rouges are frequently cleaned up:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.