this video is a star !!! i really needed it to understand FortiNAC, thanks :)
@blackknight985 Жыл бұрын
Hi there, very informative video. Do you have any other video about FortiNAC and how to deploy it please ?
@danimoosakhan9 ай бұрын
Hey, if I have a third-party downstream switch (such as Juniper) that I want to connect to upstream FortiSwitch. How can I tag all the VLANs on the FortiSwitch port that is connected to a third-party switch?
@tothepointfortinet38239 ай бұрын
On the FortiSwitch port connected to Juniper port, you would conifgure "Allowed VLAN's" and specify the VLAN's that you want communicated to the Juniper side. The allowed VLAN list for each port specifies the VLAN tag values for which the port can transmit or receive frames. See more: docs.fortinet.com/document/fortiswitch/6.4.6/administration-guide/146333/vlans-and-vlan-tagging#Allowed
@hennessy69965 ай бұрын
Hi @#ToThePoint Fortinet I noticed my onboarding VLAN has captive portal enabled by default for the VLAN, would that be necessary?
@tothepointfortinet38235 ай бұрын
Whether it's necessary would probably depend on the security that the customer expects, and the access that the firewall policy is providing.
@diegosanchez4354 Жыл бұрын
Hello, very good video. Really interesting. I have a question. If all the ports of all the switches are found in NAC mode and an attempt is made to connect a device that is not authorized, would this deny access until the NAC rule is made to allow it? basically nothing connects until it is authorized. Regards
@tothepointfortinet3823 Жыл бұрын
See 1:10 to 1:50 which covers it. the 'onboarding' VLAN is where the "non-authorized" devices are placed until it matches a NAC rule. So as long as your firewall policies don't allow any access then that will achieve the end result that you are looking for
@nustiko2 жыл бұрын
Hello, I am from France and your video are all very interresting. Very good job !! Is it possible to add many MAC addresses in the same NAS rule ? Regards Cedric
@tothepointfortinet38232 жыл бұрын
You can use wildcard to make it more scalable. I don't believe you can add many MAC addresses to the same rule though