Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jannick
New Contributor II

Secure LAN port on FP231F using NAC

Hi!

 

Recently we started a little PoC for a new project. On the project we're looking to implement a FortiGate-100E, a FortiSwitch 224E-POE and FortiAPs (we're now testing with the FP231F, but might choose other models).

 

Our goal is to have in every room an AP with 3 outgoing ports. 2 ports are for fixed devices and 1 port is for a BYOD device.

 

In our current config we're looking to use NAC. It's a powerful method and we got it fully working for wireless devices connecting to different SSIDs. The only thing we're running into right now is applying NAC to the LAN port(s) on the FortiAP.

 

By putting the FP231F into WAN-LAN modus and bridiging the LAN port to a hidden SSID configured to a specific VLAN (13), we managed to put wired connections into the LAN2 port on VLAN 13 (without NAC enabled). When enabeling NAC for the SSID, the device goes into the VLAN the AP is one while the NAC policy states it should go into VLAN 13 (in this specific case). It seems like NAC is completly not working/ignored for the wired device.

 

My question is: Is it possible to use NAC on one or more LAN ports of a FortiAP? If so, how? If not, what method would you apply to have a LAN port fully secured to a single device (like NAC with MAC, Vendor and more).

 

Thank you!

2 REPLIES 2
ebilcari
Staff
Staff

Can you specify if this request is for NAC Policies in FGT or FortiNAC as a dedicated NAC product/solution?

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Jannick
New Contributor II

My request is specifically about the NAC Policies in FGT.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors