FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
cmaheu
Staff
Staff
Article Id 195350
Description
A rogue connected to the network matches the wrong Device Profiling Rule: 
  • If matching rule is configured for automatic registration, the host is registered as the wrong device.  
  • If matching rule is configured for manual registration, the host remains rogue and is listed under Profiled Devices in the Administration UI with the wrong matching rule name.


Scope
Version: 8.x, 9.x
Solution
1.  In the Administration UI, navigate to
8.x:  Hosts > Device Profiling Rules
9.x:  Users & Hosts > Device Profiling Rules


2.  Review the following:
  • Ensure the desired rule is enabled.
  • Rule ranking - Is the matching rule ranked above the desired rule to be matched?  For ranking best practices, refer to the Device Profiler document in Fortinet Document Library.
  • Rule methods - Verify the host is not missing any required criteria in order to match the desired profiling rule.

3.  After making corrections, test the rogue against the desired rule.  Search for the MAC address in the Adapters View. 
8.x:  Hosts > Adapter View
9.x:  Users & Hosts > Adapters

Right click on the adapter record and select Test Device Profiling Rule.


4.  Once the rule matches, re-run the rogue host evaluation.
8.x:  Hosts > Device Profiling Rules and click Run
9.x:  Users & Hosts > Device Profiling Rules and click Run




Related Articles

Technical Tip: Troubleshooting rogue not matching any device profiles

Contributors