FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 195184
Description
Device Profiling to Policy assignment

Scope
Version: Network Sentry 6.x
Solution
Version: Network Sentry 6.x and above


Issue:  Device successfully registers using a Device Profiling Rule.  However, the device does not get assigned the correct VLAN.  Policy Details in Hosts > Host View displays the correct Network Access Policy.  


Solution:  Ensure the Authentication Host State is not enforced on the wireless controller/Access Point.  Devices registered via Device Profiling Rules do not authenticate.  Therefore, if Authentication is enforced, devices registered via Device Profiling Rules will be isolated to the Authentication VLAN.

1.  In Network Sentry Topology, review the Wireless Controller Model Configuration (or SSID Configuration if SSID shows Network Access of "Inherited").  
2.  Change the Authentication Access Enforcement to Bypass.





Contributors