Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
doncacciatoconsuting
New Contributor III

NAC - wired switchport default VLANs for various use cases

I'm looking for some best practices for setting the 'starting default' wired switchport vlans when deploying NAC.
 
What is reccommended for each of these cases ?
a) dead end VLAN with zero access ?
b) guest network VLAN that denies access to any corporate resources ?
c) a isolation vlan with a captive portal ?
 
1) Switchports configured for 802.1x used by corporate computer access. I have a NAC policy to identify 802.1x/TLS cert auth and change the port to a 'prod' vlan. 
 
2) Switchports dedicated to IOT devices. Device profiling will trigger a access policy to put these devices in the right vlan like camera, door badge systems, printers, etc.
 
3) Switchports dedicated for byod devices. Access policy will force the users into a registration portal w/ dissolveable agent. 
 
Thanks for any insight.
 

 

1 Solution
ebilcari

By default Windows remember the last cached credentials of the user but the access to the DCs can still be provided while the hosts are in the isolation networks. The Allowed Domain feature is used for that.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

4 REPLIES 4
AEK
SuperUser
SuperUser

In my opinion I don't think there is a specific recommendation. The best option is to discuss it with your customer.

Some customers want security more than productivity, and some others the opposite. Some others want the set default VLAN for some port to Guest VLAN, and for some other (office/VIP) ports to Prod VLAN (for productivity just in case FNAC goes down).

The point is once you explain this to your customer he will understand and "he" will decide what is the best option for his case (and for each set of ports) and what is more compliant to his company's policy.

AEK
AEK
doncacciatoconsuting

AEK, makes sense. A follow-up question....

In a windows environment, does the user need to start on a vlan that at least has access to the domain controller to authenticate before any NAC policy is applied ?

 

Thanks !

ebilcari

By default Windows remember the last cached credentials of the user but the access to the DCs can still be provided while the hosts are in the isolation networks. The Allowed Domain feature is used for that.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
doncacciatoconsuting

that's great - thanks!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors