Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jprocha
New Contributor II

FortiNAC Authentication Best Practices

Hello everyone! 

 

I am trying to get a better insight on how to set up Authentication Isolation in a more efficient way for my network. 

One issue that I currently have is the time that it takes for host to be moved to the authentication VLAN. From the configuration options, 1 minute is the least for "Time in Production Before Authentication" you can set up, so I usually get faced with the following situation:

- The user logs in to the PC and for whatever reason the logged on user can not be passed to FortiNAC, the user starts browsing for a few seconds and gets moved to Authentication VLAN and prompted with the web captive for authentication and the Persistent Agent Pop-UP asking for credentials. After following the requests the user gets redirected to the appropriate VLAN.

The thing is, a user has to go through this process daily before starting to work: Turns on the computer, gets moved from default registration to the access VLAN, then after 1 minute is moved back to Authentication VLAN where after authenticating is moved to the access VLAN once again. 

I understand that this is a security measure but wonder if there is a more efficient way to set up this whole process. (Considering all my devices have the persistent agent on them, but for different reason in some cases the agent does not perform SSO either because the user uses a login outside the domain of for some other issue with the PA).

 

One thing that passed through my mind is if there might be a way to prompt for the credentials using the PA pop-up while still on the access VLAN without the need to move the host to Authentication for example.

 

I would appreciate any tips or bets practices on how you guys perform authentication rules in your environment!

 

Regards!

FortiNAC 

jprocha
FCSS - FortiNAC - FortiSwitch
jprochaFCSS - FortiNAC - FortiSwitch
1 REPLY 1
ebilcari
Staff
Staff

The use of the Persistent Agent along with a Passive Agent rule should be sufficient to populate the logged-in user details. The 'Time in Production Before Authentication' can also be set to '0' if needed, and the 'Time Offline Before Deauthentication' can be increased to avoid frequent disruptions for the users.

If RADIUS authentication is used to gain network access, the Authentication Policy is not required.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors