FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 193863

Description

 

This article describes how to view DHCP traffic received from the production network for DHCP fingerprint data.


Scope


Version: 9.x & F7.x.


Solution

 

Option 1: Administration UI.

  1. Navigate to Users & Hosts -> Endpoint Fingerprints.
  2. To filter just DHCP traffic, select the filter icon next to the Source column header.
 

193863Fingerprintfilter.jpg

 

 


Option 2: FortiNAC CLI - Run a tcpdump and filter for port 53.

 

CentOS: 

 

  1. Login as root and run the following command:
 
tcpdump -nni eth0 port 53
 
  1. Press CTRL+C to stop the process.

 

FortiNAC-OS:

 

See Technical Tip: Run tcpdump in FNAC-F and save capture as a file.