Hi Team,
I am swapping from Cisco ISE to FortiNAC.
Currently, ISE permits access with EAP-TLS and LDAP user groups (Domain users and domain computers)
In FortiNAC, EAP-TLS authentication is possible but I don't see any option to permit access based on user/computer account at LDAP/AD.
Regards,
Barry Ghuman
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Barry
Do you mean your user-host policy is not assigning the right network to your clients?
I must assign the network to the users based on their username (fetched from the EAP-TLS certificate CN or SAN).
I don't see any option in FortiNAC that maps "Network Access" based on the LDAP group membership.
For Example:
Workstation (logical Network) - EAP-TLS (machine auth & Domain Computers)
Users (logical Network) - EAP-TLS (user auth & Domain Users)
If I remember well I was used to achieve it by creating group (AD group/computer) under menu System > Groups, then I use it to define my UHP profile in field "who/what by group", then assign the right access rule to that UHP.
Hi, I don't see anything in the NAC-F. Could you please confirm if the feature is still available?
Hello @BarryGhuman ,
the LDAP group are populated with Users once they register to the host.
You can then use the LDAP group as matching filter in the User host profile in the "who/what" setting
https://docs.fortinet.com/document/fortinac-f/7.4.0/administration-guide/15797/user-host-profiles
Check this article to understand how LDAP groups are synched and populated in FortiNAC:
If the policy is not matching based on LDAP group check this for troubleshooting:
You can also leverage computer objects and they Computer name will appear as "User" in FortiNAC.
Regards
I see it still exist on FNAC-F.
Here it is:
https://docs.fortinet.com/document/fortinac-f/7.4.0/administration-guide/781776/add-groups
Just for information the newest release of FortiNAC 7.6 has now a dedicated guide for Machine authentication:
https://docs.fortinet.com/document/fortinac-f/7.6.0/machine-authentication/478932/overview
Authentication methods supporting EAP-MSCHAPV2 and EAP-TLS
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.