NAC Control with FortiGate + FortiSwitch

Поделиться
HTML-код
  • Опубликовано: 24 июл 2024
  • Basic NAC (Network Access Control) with FortiGate + FortiSwitch.
    0:00 Example1: NAC based on MAC Address
    3:35 Example2: NAC based on Operating System
  • НаукаНаука

Комментарии • 8

  • @bassentmostafa3121
    @bassentmostafa3121 Год назад +2

    this video is a star !!! i really needed it to understand FortiNAC, thanks :)

  • @blackknight985
    @blackknight985 Год назад +1

    Hi there, very informative video. Do you have any other video about FortiNAC and how to deploy it please ?

  • @diegosanchez4354
    @diegosanchez4354 Год назад +1

    Hello, very good video. Really interesting. I have a question.
    If all the ports of all the switches are found in NAC mode and an attempt is made to connect a device that is not authorized, would this deny access until the NAC rule is made to allow it?
    basically nothing connects until it is authorized.
    Regards

    • @tothepointfortinet3823
      @tothepointfortinet3823  Год назад +1

      See 1:10 to 1:50 which covers it. the 'onboarding' VLAN is where the "non-authorized" devices are placed until it matches a NAC rule. So as long as your firewall policies don't allow any access then that will achieve the end result that you are looking for

  • @nustiko
    @nustiko Год назад

    Hello, I am from France and your video are all very interresting. Very good job !!
    Is it possible to add many MAC addresses in the same NAS rule ?
    Regards
    Cedric

    • @tothepointfortinet3823
      @tothepointfortinet3823  Год назад +1

      You can use wildcard to make it more scalable. I don't believe you can add many MAC addresses to the same rule though

  • @danimoosakhan
    @danimoosakhan 3 месяца назад

    Hey, if I have a third-party downstream switch (such as Juniper) that I want to connect to upstream FortiSwitch. How can I tag all the VLANs on the FortiSwitch port that is connected to a third-party switch?

    • @tothepointfortinet3823
      @tothepointfortinet3823  3 месяца назад

      On the FortiSwitch port connected to Juniper port, you would conifgure "Allowed VLAN's" and specify the VLAN's that you want communicated to the Juniper side. The allowed VLAN list for each port specifies the VLAN tag values for which the port can transmit or receive frames.
      See more:
      docs.fortinet.com/document/fortiswitch/6.4.6/administration-guide/146333/vlans-and-vlan-tagging#Allowed