How it Works
Visibility
FortiNAC learns where endpoints are connected on the network using the following methods:
-
RADIUS communication
-
L2 Polling (MAC address table read)
-
L3 Polling (ARP cache read)
Control
FortiNAC provisions an endpoint’s network access by managing VLAN assignments based on the controller’s model configuration or an applicable network access policy and the host state of the device. The VLAN configuration is modified using the appropriate method based upon the vendor and model (see chart below).
Device Support Methods
Endpoint Connectivity Notification |
Reading MAC Address Tables (L2 Poll) |
Reading IP Tables (L3 Poll) |
Reading VLANs |
VLAN Assignment |
Reading SSIDs |
De-auth |
RADIUS (802.1x or MAC-auth) |
SNMP |
SNMP |
CLI (VLAN and Role) |
RADIUS |
SNMP |
CLI |