FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
cmaheu
Staff
Staff
Article Id 193566
Description
Certain levels of access is required for the appliance to correctly model the device and perform basic tasks.  Depending upon the device, the appliance uses a combination of SNMP, CLI and API.  For the specific methods used per device, see table below.    


SNMP Account Requirements
SNMP community name (v1/v2) or account (v3)
- Devices requiring control (changing VLANs, etc):  Read/write privileges 
- L3 devices providing ARP information only: Read privileges


CLI Account Requirements 
When configuring the device itself, use only letters, numbers and hyphens (-) in names for items within the device configuration, in security strings and in SNMP credentials. Other characters may prevent the device configuration from being read properly. For example, in many cases the # sign is interpreted by FortiNAC as a prompt. Cisco restricts the use of @ and #.

- Devices requiring control (changing VLANs, etc):  Read/write privileges (Cisco must be level 15 local user account) 
- L3 devices providing ARP information only: Read access (level 7)


API Account Requirements 
- Devices requiring control (changing VLANs, etc):  Full Read/write permissions 
- L3 devices providing ARP information only: Read permissions



Required Accounts

Vendor/Model

Accounts

3Com

SNMP, CLI

3Com Baseline and VSeries

SNMP Only

Adtran WLC

SNMP, REST API - See Integration Guide

Aerohive

SNMP, CLI - See Integration Guide

Alcatel Omni

SNMP (few may CLI)

Allied Telesyn

SNMP Only

Aruba Controllers

SNMP, CLI - See Integration Guide

Aruba IAP

SNMP, CLI - See Integration Guide

Aruba SSeries Switch

SNMP, CLI

BayStack ( Old Nortel )

SNMP Only

Brocade/Foundry

SNMP, CLI

Cisco Aironet APs

SNMP, CLI

Cisco ASA

SNMP, CLI - See Integration Guide

Cisco SG Switch

SNMP, CLI

Cisco Wired

SNMP, CLI

Cisco WLC/Airespace

SNMP, CLI - See Integration Guide

Dell

SNMP, CLI

D-Link

SNMP, CLI

Enterasys

SNMP, CLI

Enterasys B/C/D/N/S/X ( newer )

SNMP, CLI

Extreme

SNMP, CLI

Force10

SNMP, CLI

Fortinet FortiAP

SNMP, REST API - See Integration Guide

Fortinet Fortigate

SNMP, CLI, REST API - See Integration Guide

Fortinet FortiSwitch

SNMP, REST API - See Integration Guide

Fortinet FortiWLC

SNMP, CLI - See Integration Guide

Enterasys, Extreme HiPath Controller

SNMP, CLI - See Integration Guide

HP MSM Wireless

SNMP, CLI - See Integration Guide

HP ProCurve

SNMP

HP Unified Controllers

SNMP Only - See Integration Guide

Juniper EX Switches

SNMP, CLI - See Integration Guide

Meraki Wireless

SNMP Only - See Integration Guide

Meraki Switch

SNMP, REST API - See Integration Guide

Mist

REST API Only - See Integration Guide

Motorola/Symbol/Brocade wireless

SNMP, CLI - See Integration Guide

Nortel/Avaya

SNMP, CLI

Palo Alto

SNMP, CLI

Passport

SNMP, CLI

Ruckus Wireless

SNMP Only - See Integration Guide

Sonic Wall

SNMP, CLI

Trapeze

SNMP, CLI - See Integration Guide

Ubiquiti

SNMP, CLI - See Integration Guide

Xirrus

SNMP, CLI - See Integration Guide



Related Articles

Technical Tip: Issues using '#' character in CLI banner

Technical Note: Troubleshooting SNMP communication issues

Technical Note: Troubleshooting CLI credential failure

Contributors