Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bootaan26
New Contributor III

Fortinac registeration enforcement hosts connected to hub or unmanaged switch

Hi guys,

 

is it possible to enforce registration/isolation vlan  for the devices connected to the hub or unmanaged switch?

All devices connected to the managed switches are working fine once i enforce to the isolation vlan and the captive portal is working fine but don't know about the hub.

 

Thanks 

 

 

1 Solution
AEK

Hi Bootaan

I think they should be able to register.

But as I said, while there is at least one unregistered host connected to the hub, all registered hosts that are plugged to the same hub will remain in isolation. Once all are registered they will be all put in prod VLAN.

AEK

View solution in original post

AEK
5 REPLIES 5
AEK
SuperUser
SuperUser

Hi bootaan

Unmanaged switch is not intended to stay in your network if you want to secure it with NAC solution.

The unmanaged switch or hub can't have its ports controlled by NAC.

However, if the hub's uplink is connected to a controlled port of a managed switch, and you connect a rogue device to the hub, then that controlled port will be put in isilation, so all hub ports will be in isolation.

Also in case you plug to the hub both a registered device and a rogue device, then they will both be put in isolation.

AEK
AEK
bootaan26
New Contributor III

Hi AEK,

 

Thanks for the clarification of the issue.

if I enforce isolation vlan to the uplink of hub's port, will the devices connected to the hub ports able to register through captive portal or I can register from fortinac host view?

 

AEK

Hi Bootaan

I think they should be able to register.

But as I said, while there is at least one unregistered host connected to the hub, all registered hosts that are plugged to the same hub will remain in isolation. Once all are registered they will be all put in prod VLAN.

AEK
AEK
bootaan26
New Contributor III

Hi AEK, 

 

Thanks for your assistance, really appreciate it.

I have tested and it's working fine as you mentioned.

 

 

 

 

 

ebilcari

When the hub is connected to a fully managed switch that supports multiple dynamic VLANs on a single port (MAC-based VLANs), RADIUS can be used to assign separate VLANs to each host. However, this solution can be somewhat complex to implement and depends on the capabilities of the managed switch 

In addition you can also configure Access point management as shown in this article but this is not considered a true isolation method and it is deprecated in latest version of FNAC 7.6.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors