Hi!
Recently we started a little PoC for a new project. On the project we're looking to implement a FortiGate-100E, a FortiSwitch 224E-POE and FortiAPs (we're now testing with the FP231F, but might choose other models).
Our goal is to have in every room an AP with 3 outgoing ports. 2 ports are for fixed devices and 1 port is for a BYOD device.
In our current config we're looking to use NAC. It's a powerful method and we got it fully working for wireless devices connecting to different SSIDs. The only thing we're running into right now is applying NAC to the LAN port(s) on the FortiAP.
By putting the FP231F into WAN-LAN modus and bridiging the LAN port to a hidden SSID configured to a specific VLAN (13), we managed to put wired connections into the LAN2 port on VLAN 13 (without NAC enabled). When enabeling NAC for the SSID, the device goes into the VLAN the AP is one while the NAC policy states it should go into VLAN 13 (in this specific case). It seems like NAC is completly not working/ignored for the wired device.
My question is: Is it possible to use NAC on one or more LAN ports of a FortiAP? If so, how? If not, what method would you apply to have a LAN port fully secured to a single device (like NAC with MAC, Vendor and more).
Thank you!
Can you specify if this request is for NAC Policies in FGT or FortiNAC as a dedicated NAC product/solution?
My request is specifically about the NAC Policies in FGT.
User | Count |
---|---|
2624 | |
1393 | |
804 | |
670 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.