Trying to wrap my head around what happens if a remote site goes down and cannot reach FortiNAC ?
I'm assuming that the existing switch or AP config will remain in it's current state...
What happens when a rogue host tries to connect to the LAN ?
What happens when a registered host tries to connect ?
Any other considerations ?
Thanks !
Hi
In case of FNAC goes down, "usually" companies prefer productivity on security, it means they prefer when a host connects it falls in the prod VLAN even if it can be against security policy. This is because companies can't accept a general panic situation (no one has access to network), just because FNAC is down.
So regarding LAN hosts (wire network), you can achieve this just by setting prod VLAN as default VLAN (under Network > Inventory > Switch > Port Properties).
And for WiFi, you may add your Windows NPS as a secondary RADIUS server, and in the same time set the prod VLAN as default VLAN in your wireless controller. This will make your WLC contact your NPS in case FNAC is down in order to authenticate the users, and it will assign the prod VLAN to the connected clients.
Hope this helps.
Basically yes, every new change in the network or host enforcement will not be reflected.
Connected hosts will not be affected, rogues will not be able to reach the portal and registered hosts will not be able to authenticate or if authentication is not configured will stay in their original VLAN.
If you are referring to a remote site that losses access to the HQ completely, some fallback mechanisms to allow internet access can be configured on the local network devices.
FNAC supports HA (active/passive) and is recommended for environments that require availability. In the latest firmware branch (7.6) N+1 Failover is also supported.
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.