Created on 09-28-2018 07:55 AM Edited on 03-27-2024 05:10 AM By Anthony_E
Description
Scope
FortiNAC-F, FortiNAC
Solution
Log output in output.master:
yams.HostServer FINER :: 2024-03-27 11:51:37:270 :: #786 :: HostServer.updateHost(DESKTOP-FL3MH7T jdoe 00:15:5D:E4:1F:3B) starting
yams.HostServer FINER :: 2024-03-27 11:51:37:270 :: #786 :: HostServer.updateHost() autoCreate = false host = DESKTOP-FL3MH7T jdoe 00:15:5D:E4:1F:3B type = Server host type = 8
yams.HostServer FINER :: 2024-03-27 11:51:37:270 :: #786 :: HostServer.updateHost() DESKTOP-FL3MH7T jdoe 00:15:5D:E4:1F:3B updating OS to Server Windows
yams.HostServer FINER :: 2024-03-27 11:51:37:270 :: #786 :: HostServer.updateHost() updating host. host = DESKTOP-FL3MH7T jdoe 00:15:5D:E4:1F:3B
com.bsc.plugin.dynamic.HostServer.update() starting: object id = 17yams.HostServer FINER :: 2024-03-27 11:51:37:270 :: #786 :: Changes =
{128=Server Windows, 4398046511104=Server}
yams.HostServer FINER :: 2024-03-27 11:51:37:270 :: #786 :: HostServer.setRole() role = IT
yams.HostServer FINER :: 2024-03-27 11:51:37:270 :: #786 :: oldHost type = 8
yams.HostServer FINER :: 2024-03-27 11:51:37:270 :: #786 :: newHost type = 8
com.bsc.plugin.dynamic.HostServer replace(17) starting replaceCount = 72yams.HostServer FINER :: 2024-03-27 11:51:37:272 :: #786 :: replace wrote 17, ready to call listeners
yams.HostServer FINER :: 2024-03-27 11:51:37:272 :: #786 :: checkListeners called for object 17, #listeners = 4, type = 3
yams.HostServer FINER :: 2024-03-27 11:51:37:272 :: #786 :: old object = Host Record:
Landscape = 91769544454 00:15:5D:E4:1F:06
ID = 17
hostName = DESKTOP-FL3MH7T
owner = jdoe
policy = null
os = Windows
hardwareType =
application = null
notes = null
Creation Time = Wed Mar 27 11:51:18 CET 2024
Expiration Date =
Inactivity = 1 Days
Inactivity Date =
Last Successful Poll = Never Been Polled
Status = Connected
loggedOnUserId = jdoe
patchManagementVendor = null
patchManagementID = null
role = IT
Figure 3. Host added as member of group
Verify the host attributes and role in FortiNAC CLIS as follows:
dumphostrecords -mac 00:15:5D:E4:1F:3B
Host Record:
Landscape = 91769544454 00:15:5D:E4:1F:06
ID = 18
hostName = DESKTOP-FL3MH7T
owner = jdoe
policy = null
os = Server Windows
Status = Connected
loggedOnUserId = jdoe
patchManagementVendor = null
patchManagementID = null
role = IT
.
.
Adapter[0] = 00:15:5D:E4:1F:3B
At this point, both Role and group membership can be used as matching criteria for Network access policies.
Related article:
Technical Tip: What causes a host to be moved to an imported LDAP Host Group
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.