FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 189443
Description
Hosts Can Access the Internet from Registration / Isolation Network

Solution
Issue:
Hosts with static DNS settings configured may be able to access the internet from the Registration / Isolation networks. Static DNS settings are configured in the IPv4 Properties of the adapter. Network Sentry isolates hosts by using DNS redirection so a static DNS setting on the end station may appear to circumvent this isolation.

Solution:
Configure the Registration / Isolation network ACLs to only allow port 53 traffic (DNS) to Network Sentry's Ethernet 1 ip address (Registration / Isolation). 



Contributors