Hi guys,
is it possible to enforce registration/isolation vlan for the devices connected to the hub or unmanaged switch?
All devices connected to the managed switches are working fine once i enforce to the isolation vlan and the captive portal is working fine but don't know about the hub.
Thanks
Solved! Go to Solution.
Hi Bootaan
I think they should be able to register.
But as I said, while there is at least one unregistered host connected to the hub, all registered hosts that are plugged to the same hub will remain in isolation. Once all are registered they will be all put in prod VLAN.
Hi bootaan
Unmanaged switch is not intended to stay in your network if you want to secure it with NAC solution.
The unmanaged switch or hub can't have its ports controlled by NAC.
However, if the hub's uplink is connected to a controlled port of a managed switch, and you connect a rogue device to the hub, then that controlled port will be put in isilation, so all hub ports will be in isolation.
Also in case you plug to the hub both a registered device and a rogue device, then they will both be put in isolation.
Hi AEK,
Thanks for the clarification of the issue.
if I enforce isolation vlan to the uplink of hub's port, will the devices connected to the hub ports able to register through captive portal or I can register from fortinac host view?
Hi Bootaan
I think they should be able to register.
But as I said, while there is at least one unregistered host connected to the hub, all registered hosts that are plugged to the same hub will remain in isolation. Once all are registered they will be all put in prod VLAN.
Hi AEK,
Thanks for your assistance, really appreciate it.
I have tested and it's working fine as you mentioned.
When the hub is connected to a fully managed switch that supports multiple dynamic VLANs on a single port (MAC-based VLANs), RADIUS can be used to assign separate VLANs to each host. However, this solution can be somewhat complex to implement and depends on the capabilities of the managed switch
In addition you can also configure Access point management as shown in this article but this is not considered a true isolation method and it is deprecated in latest version of FNAC 7.6.
User | Count |
---|---|
2331 | |
1262 | |
772 | |
453 | |
436 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.