Join the discussion
Question 11/27
When configuring FortiNAC-F to manage FortiGate VPN users, an endpoint compliance policy must be created for the integration.
Why is the endpoint compliance policy necessary for this type of integration?
Why is the endpoint compliance policy necessary for this type of integration?
Correct Answer: A
The integration of FortiNAC-F withFortiGate VPNrequires a specific policy workflow to bridge the gap between initial user authentication and full network access. When a user connects to the VPN, the FortiGate typically provides the User ID and IP address, but FortiNAC-F requires aMAC addressto uniquely identify and manage the endpoint ' s record.
According to theFortiGate VPN Integration Guide, theEndpoint Compliance Policyis a mandatory component of this setup because it is used todesignate the required agent type. Because a VPN connection is Layer 3, FortiNAC cannot " see " the MAC address through traditional SNMP or L2 polling. The compliance policy instructs the system to present aCaptive Portalto the remote user, requiring them to download and run either thePersistentorDissolvable Agent. The agent then reports the device ' s MAC address back to FortiNAC, allowing the system to correlate the VPN session with a host record.
Once the agent is running and the MAC is known, FortiNAC-F can evaluate the device ' s security posture (if scanning is configured) and send the necessaryFSSO tagsback to the FortiGate to lift the initial network restrictions. Without the compliance policy to enforce the agent requirement, the connection would remain in an isolated " IP-only " state with no unique hardware identity.
" TheEndpoint Compliance Policyis necessary to control the agent requirement for VPN users. Create a default VPN Endpoint Compliance Policy todistribute an agentvia captive portal for isolated machines. This policy allows the administrator todesignate the required agent type(Persistent or Dissolvable) that will be used to collect the hardware (MAC) address and perform health scans on the remote endpoint. " -FortiNAC FortiGate VPN Integration Guide: Default Endpoint Compliance Policy (Optional) Section.
According to theFortiGate VPN Integration Guide, theEndpoint Compliance Policyis a mandatory component of this setup because it is used todesignate the required agent type. Because a VPN connection is Layer 3, FortiNAC cannot " see " the MAC address through traditional SNMP or L2 polling. The compliance policy instructs the system to present aCaptive Portalto the remote user, requiring them to download and run either thePersistentorDissolvable Agent. The agent then reports the device ' s MAC address back to FortiNAC, allowing the system to correlate the VPN session with a host record.
Once the agent is running and the MAC is known, FortiNAC-F can evaluate the device ' s security posture (if scanning is configured) and send the necessaryFSSO tagsback to the FortiGate to lift the initial network restrictions. Without the compliance policy to enforce the agent requirement, the connection would remain in an isolated " IP-only " state with no unique hardware identity.
" TheEndpoint Compliance Policyis necessary to control the agent requirement for VPN users. Create a default VPN Endpoint Compliance Policy todistribute an agentvia captive portal for isolated machines. This policy allows the administrator todesignate the required agent type(Persistent or Dissolvable) that will be used to collect the hardware (MAC) address and perform health scans on the remote endpoint. " -FortiNAC FortiGate VPN Integration Guide: Default Endpoint Compliance Policy (Optional) Section.
Add Comments
- Other Question (27q)
- Q1. During an evaluation of state-based enforcement, an administrator discovers that ports tha...
- Q2. Refer to the exhibit. (Exhibit) After a successful layer 2 poll, two hosts were learned on...
- Q3. Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)...
- Q4. Which two actions must the administrator perform to allow FortiNAC-F to process incoming s...
- Q5. While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen...
- Q6. When creating a user or host profile, which three criteria can you apply? (Choose three.)...
- Q7. Refer to the exhibit. (Exhibit) If a host is connected to a port in the Building 1 First F...
- Q8. Refer to the exhibit. (Exhibit) An administrator wants to ensure that guest accounts creat...
- Q9. Refer to the exhibits. (Exhibit) What would happen if the highlighted port with connected ...
- Q10. While troubleshooting a network connectivity issue, an administrator determines that a dev...
- Q11. When configuring FortiNAC-F to manage FortiGate VPN users, an endpoint compliance policy m...
- Q12. An administrator wants to control user access to corporate resources by integrating FortiN...
- Q13. An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic a...
- Q14. Two FortiNAC-F devices have been configured as a 1 + 1 HA pair. The primary server went of...
- Q15. Refer to the exhibit. (Exhibit) An administrator has configured the DHCP scope for a regis...
- Q16. An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deplo...
- Q17. When working with a FortiNAC-F Manager and cluster management, what will occur when a clus...
- Q18. Refer to the exhibits. (Exhibit) An administrator is troubleshooting visibility issues on ...
- Q19. An administrator wants to create a conference manager administrator account but would like...
- Q20. Refer to the exhibit. (Exhibit) What would FortiNAC-F generate if only one of the security...
- Q21. Refer to the exhibit. (Exhibit) An administrator wants to use FortiNAC-F to automatically ...
- Q22. What must an administrator configure to allow FortiNAC-F to process incoming syslog messag...
- Q23. When preparing network infrastructure devices for visibility, what are the two main advant...
- Q24. A user was attempting to register their host through the registration captive portal. Afte...
- Q25. When managing multiple FortiNAC-F CAs with a FortiNAC-F Manager, how is endpoint informati...
- Q26. Refer to the exhibit. A FortiNAC-F N+1 HA configuration is shown. (Exhibit) What will occu...
- Q27. An administrator wants to build a security rule that will quarantine contractors who attem...
[×]
Download PDF File
Enter your email address to download Fortinet.NSE5_FNC_AD_7.6.v2026-07-18.q27.pdf
