Hello everyone!
I am trying to get a better insight on how to set up Authentication Isolation in a more efficient way for my network.
One issue that I currently have is the time that it takes for host to be moved to the authentication VLAN. From the configuration options, 1 minute is the least for "Time in Production Before Authentication" you can set up, so I usually get faced with the following situation:
- The user logs in to the PC and for whatever reason the logged on user can not be passed to FortiNAC, the user starts browsing for a few seconds and gets moved to Authentication VLAN and prompted with the web captive for authentication and the Persistent Agent Pop-UP asking for credentials. After following the requests the user gets redirected to the appropriate VLAN.
The thing is, a user has to go through this process daily before starting to work: Turns on the computer, gets moved from default registration to the access VLAN, then after 1 minute is moved back to Authentication VLAN where after authenticating is moved to the access VLAN once again.
I understand that this is a security measure but wonder if there is a more efficient way to set up this whole process. (Considering all my devices have the persistent agent on them, but for different reason in some cases the agent does not perform SSO either because the user uses a login outside the domain of for some other issue with the PA).
One thing that passed through my mind is if there might be a way to prompt for the credentials using the PA pop-up while still on the access VLAN without the need to move the host to Authentication for example.
I would appreciate any tips or bets practices on how you guys perform authentication rules in your environment!
Regards!
The use of the Persistent Agent along with a Passive Agent rule should be sufficient to populate the logged-in user details. The 'Time in Production Before Authentication' can also be set to '0' if needed, and the 'Time Offline Before Deauthentication' can be increased to avoid frequent disruptions for the users.
If RADIUS authentication is used to gain network access, the Authentication Policy is not required.
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.