FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 196934
Description
Headless Devices Marked as Needing Authentication and Isolated

Scope
Version:   Network Sentry 7 & 8
Solution
Version:  Network Sentry 7 and 8

Issue:  Any Host registered in the Hosts View (including headless devices) can be marked for Authentication and Isolated if the following conditions are met:
1. The host is connected to a network device on which Network Sentry is enforcing authentication.   
  • A wired port that is a member of the Forced Authentication group.
  • A wireless controller or access point whose SSID or Model configuration has Authentication set to Enforce.
2. The affected host matches an Authentication Policy. 


Workaround:
Option 1.  Add the headless devices to the Forced User Authentication Exceptions group or a group nested under Forced User Authentication Exceptions.
Option 2.  Redesign the User/Host Profile for Authentication in a manner to which the impacted headless devices will not match.

Contributors