FortiNAC — Network Access Control
Basic Information
| Field | Value |
|---|---|
| Category | Infrastructure |
| Owner | Filip Kohák |
| Deputy | Artem Ryzhkov |
| SLA | 24x7 |
| Deployment | On-prem VM (Proxmox cluster) |
Description
FortiNAC controls who and what device can connect to the corporate network. Authentication uses 802.1X standard on Wi-Fi access points (Aruba/UniFi). Integration with Entra ID and Active Directory automatically assigns VLANs based on user role.
Key features:
- 802.1X authentication (Wi-Fi and wired network)
- Automatic VLAN assignment based on AD/Entra ID group membership
- Detection and isolation of unknown devices (guest VLAN)
- Device profiling (OS fingerprinting)
- FortiGate integration for dynamic security policies
Access and Login
- URL:
https://[fortinac-vm-ip](management VLAN only) - Login: admin account (stored in Passbolt)
- VM access: via Proxmox console or SSH
Warning
Changes to NAC configuration can cause Wi-Fi outage for all users. Perform major changes (new VLAN policies, RADIUS settings) during maintenance windows (outside business hours).
Procedure — Approve New Device
- Log in to FortiNAC GUI
- Go to Network Access → Hosts
- Search by MAC address or hostname
- Click device → Register or assign to the correct group
- Device automatically receives access to the appropriate VLAN
VLAN Assignment Mapping
| AD Group | VLAN |
|---|---|
| IT-Staff | VLAN 10 (Management) |
| Employees | VLAN 20 (Corporate) |
| Guests | VLAN 30 (Guest/Internet only) |
| Unknown | Quarantine VLAN |
Troubleshooting
| Problem | Solution |
|---|---|
| User cannot connect to Wi-Fi | Check RADIUS logs in FortiNAC: Logs → RADIUS Accounting; verify user's AD groups |
| Device stuck in Quarantine VLAN | Register device in FortiNAC or check certificate (EAP-TLS) |
| RADIUS timeout | Verify AP → FortiNAC network connectivity; check RADIUS secret (must match on both sides) |
| 802.1X fails after password change | User must manually refresh Wi-Fi profile or restart device |
Related Guides
- Active Directory — source of groups for VLAN mapping
- FortiGate — integration for dynamic policies
- Wi-Fi AP — AP configuration for 802.1X
- Proxmox — FortiNAC VM host
Contact
- Owner: Filip Kohák — Slack
@filip/ filip.kohak@etnetera.cz - Deputy: Artem Ryzhkov — Slack
@artem - Urgent incidents (Wi-Fi outage): Slack
#it-alerts