Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
doncacciatoconsuting
Contributor

Site survivability when NAC is unreachable

FortiNAC 

 

Trying to wrap my head around what happens if a remote site goes down and cannot reach FortiNAC ?

 

I'm assuming that the existing switch or AP config will remain in it's current state...

 

What happens when a rogue host tries to connect to the LAN ?

What happens when a registered host tries to connect ? 

 

Any other considerations ?

 

Thanks !

2 REPLIES 2
AEK
SuperUser
SuperUser

Hi

In case of FNAC goes down, "usually" companies prefer productivity on security, it means they prefer when a host connects it falls in the prod VLAN even if it can be against security policy. This is because companies can't accept a general panic situation (no one has access to network), just because FNAC is down.

So regarding LAN hosts (wire network), you can achieve this just by setting prod VLAN as default VLAN (under Network > Inventory > Switch > Port Properties).

And for WiFi, you may add your Windows NPS as a secondary RADIUS server, and in the same time set the prod VLAN as default VLAN in your wireless controller. This will make your WLC contact your NPS in case FNAC is down in order to authenticate the users, and it will assign the prod VLAN to the connected clients.

Hope this helps.

AEK
AEK
ebilcari
Staff
Staff

Basically yes, every new change in the network or host enforcement will not be reflected.

Connected hosts will not be affected, rogues will not be able to reach the portal and registered hosts will not be able to authenticate or if authentication is not configured will stay in their original VLAN.

If you are referring to a remote site that losses access to the HQ completely, some fallback mechanisms to allow internet access can be configured on the local network devices.

FNAC supports HA (active/passive) and is recommended for environments that require availability. In the latest firmware branch (7.6) N+1 Failover is also supported.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors