FCSS_LED_AR-7.6 · Question #77
Refer to the exhibits. A NAC policy has been configured to apply traffic that flows through FortiSwitch port 2. Traffic that meets the NAC policy criteria will be assigned to the Students VLAN…
The correct answer is A. Port2 Access mode should be set to NAC mode. From the exhibits: FortiSwitch Ports viewshows: Native VLAN: Students Allowed VLANs: quarantine.fortilink (quarantine) NAC policy "Training": Switch FortiLink: fortilink Matching criteria: MAC Address: 70:88:6b:8c:4b:0e (enabled) Operating System:Linux(enabled) Switch…
Question
Refer to the exhibits. A NAC policy has been configured to apply traffic that flows through FortiSwitch port 2. Traffic that meets the NAC policy criteria will be assigned to the Students VLAN. However, the NAC policy does not seem to be taking effect. Which configuration is missing?
Exhibit
Options
- APort2 Access mode should be set to NAC mode.
- BThe MAC address or OS might be misconfigured for the connected device.
- CPort2 Access mode should be set to Port Policy mode.
- DThe Students VLAN should be set to Allowed VLANs instead of Native VLAN.
How the community answered
(59 responses)- A85% (50)
- B8% (5)
- C5% (3)
- D2% (1)
Explanation
From the exhibits: FortiSwitch Ports viewshows: Native VLAN: Students Allowed VLANs: quarantine.fortilink (quarantine) NAC policy "Training": Switch FortiLink: fortilink Matching criteria: MAC Address: 70:88:6b:8c:4b:0e (enabled) Operating System:Linux(enabled) Switch Controller Action: Assign VLAN = Students Bounce Port = enabled Device with that MAC + OS Linux, when plugged intoport2, should be dynamically moved to VLANStudentsby the NAC policy. Why it doesn't work now On FortiLink NAC,dynamic NAC decisions only apply on ports whose "Access Mode" is set to NAC mode = FortiGate controls theonboarding VLAN, evaluates NAC policies, and then dynamically reassigns the switch port VLAN (access, quarantine, etc.). Static mode(what we see on port2) means the port just uses its configurednative/allowed VLANs, andno NAC classificationhappens. port2 is astatic access portwith Native VLAN = Students. The NAC policy exists, butFortiSwitch is not in NAC enforcement mode on that port, so the policy is never evaluated for traffic on port2. Therefore, themissing configurationis: Set port2 to NAC mode(sometimes called "Access mode: NAC" or "NAC LAN edge port"). Once port2 is changed to NAC mode: Device initially lands in the onboarding/quarantine VLAN. FortiGate collects device info (MAC, OS, etc.). NAC policy "Training" matches MAC + Linux. Switch controller actionAssign VLAN = Studentsis applied. Port is bounced (if configured), bringing the device back up in VLAN Students.
Topics
Community Discussion
No community discussion yet for this question.
