FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 190109

Description


This article describes about hosts marked as disabled are still able to connect to the production network.

 

Scope


Version:  All

 

Solution

 

Ensure Dead-End role/VLAN is configured in the AP model and the state is enforced.
 
v9 and above
1.  In the Administration UI, navigate to Network - > Inventory.
2.  Select on the Controller/AP Mode.
3.  Select the Model Configuration tab.
     or
     Select on the SSIDs tab, right click on the applicable SSID and select SSID Configuration.
4.  Set state for DeadEnd to Enforce, and Access Value to the role/VLAN designated for DeadEnd isolation.
5.  Save.
 
v8
1.  In the Administration UI, navigate to Devices - > Topology.
2.  Select on the Controller/AP Mode.
3.  Right click and select Model Configuration.
     or
     Select on the SSIDs tab, right click on the applicable SSID and select SSID Configuration.
4.  Set state for DeadEnd to Enforce, and Access Value to the role/VLAN designated for DeadEnd isolation.
5.  Save.
 

Related KB Articles

Technical Note: Disabled wired hosts not isolated

Contributors