Fortinet white logo
Fortinet white logo

Administration Guide

7.2.0

What's new in FortiNAC F 7.2.0

What's new in FortiNAC F 7.2.0

FortiNAC software re-versioning

FortiNAC software re-versions to F 7.2 to match the Fortinet fabric. The label “F” in F 7.2 is added to indicate that this is Fortinet Fabric versioning, distinct from the FortiNAC 7.2 that was previously released.

Infrastructure upgrades

An infrastructure change has been made and a new product offering is available for the FortiNAC solution. The new FortiNAC appliances are being labeled FortiNAC-F.

  • New SKU

    FortiNAC Control and Application eXtended VM (SKU FNC-CAX-VM) is the continuation and extension of the FortiNAC Control and Application VM, supporting FortiNAC version F 7.2.

    FortiNAC Manager eXtended VM (SKU FNC-MX-VM) is the continuation and extension of the FortiNAC Manager VM, supporting FortiNAC F 7.2.

  • New operating system: CentOS is replaced with a FortiOS-like OS (FortiNAC-OS)

    The previous CentOS 7 Operating System is replaced with a custom Linux image with a CLI similar to that of FortiOS. It is called FortiNAC-OS in the documentation.

    FortiNAC-OS is implemented as a firmware image, similar to other Fortinet products (i.e. FortiGate).

    MySQL is replaced with MariaDB.

  • An appliance migration is required to move an existing system on CentOS to the new FNC-CAX or FNC-MX system.

  • Software Compatibility

FortiNAC Products

Description

Operating System

Version 8.x

Version 9.x

Version F7.2

Name: FortiNAC-Control-and-Application-VM

SKU: FNC-CA-VM

FortiNAC Control and Application

Virtual Server

CentOS

Yes

Yes

Yes

Name: FortiNAC-Manager-VM

SKU: FNC-M-VM

FortiNAC Manager Virtual Server

CentOS

Yes

Yes

Yes

Name: FortiNAC-CA-500C

SKU: FNC-CA-500C

Name: FortiNAC-CA-600C

SKU: FNC-CA-600C

Name: FortiNAC-CA-700C

SKU: FNC-CA-700C

FortiNAC 500C/600C/700C, Network Control and Application Server with RAID and Redundant Power Supplies

CentOS

Yes

Yes

Yes

Name: FortiNAC-M-550C

SKU: FNC-M-550C

FortiNAC Manager 550 Server Server with RAID and Redundant Power Supplies

CentOS

Yes

Yes

Yes

FortiNAC-F Products

Description

Operating System

Version 8.x

Version 9.x

Version F7.2

Name: FortiNAC-Control-and-Application-eXtended-VM

SKU: FNC-CAX-VM

FortiNAC Control and Application

next-gen Virtual Server

FortiNAC-OS

No

No

Yes

Name: FortiNAC-Manager-eXtended-VM

SKU: FNC-MX-VM

FortiNAC Manager next-gen Virtual Server

FortiNAC-OS

No

No

Yes

Name: FortiNAC-CA-500F SKU: FNC-CA-500F FortiNAC Network Control and Application Server (F Series) FortiNAC-OS No No vF7.2.3 and greater
Name: FortiNAC-CA-600F SKU: FNC-CA-600F FortiNAC High Performance Network Control and Application Server (F Series) FortiNAC-OS No No vF7.2.3 and greater
Name: FortiNAC-CA-700F SKU: FNC-CA-700F FortiNAC Ultra High Performance Network Control and Application Server (F Series) FortiNAC-OS No No vF7.2.3 and greater
Name: FortiNAC-M-550F SKU: FNC-M-550F FortiNAC Network Manager (F Series) FortiNAC-OS No No vF7.2.3 and greater

SAML/Shibboleth support with FortiNAC-OS no longer available

Due to vulnerabilities, FortiNAC-OS does not currently support SAML/Shibboleth. Support is scheduled to be added in a future release.

FortiNAC AWS secure deployment in cloud

FortiNAC F 7.2 changes its onboarding process to integrate with AWS to set up SSH keys during image deployment. The FortiNAC appliance is now cloud-aware and will identify the cloud it is running on during boot, read any provided metadata from the cloud, and initialize accordingly.

Cloud-init functionality with FortiNAC-OS

FortiNAC F 7.2 adds the ability to bootstrap the initial configuration of the FortiNAC Virtual Machines, compatible with AWS, KVM, ESX, and Hyper-V VMs.

As part of "cloud-init," the user can run CLI commands to set the access credentials.

For more information, see the updated deployment guide for the appropriate appliance.

MAC OSX Agents

MAC OSX Agents updated to be natively compatible with M1 processor.

Report enforced and non-enforced ports

Added ability to report both enforced and non-enforced ports and AP's/SSID's

New Visualization added to the Network Device Summary dashboard tile, as well as Network Inventory.

Device Support

New Device Integration for Cambium cnPilot series of AP

SNMP MAC-Notification trap support for Dell EMC Networking N3248P-ON Ver 6.7+

Support for Extreme Campus Controller E3120

UI/UX/Workflow enhancements

FortiGate VDOM modeling enhancements

UI changes to policy creation

Policy and Logical Networks views are upgraded to the new UI, adding a common table search/filtering/drag-and-drop. The following views have been changed:

  • Supplicant EasyConnect

  • Endpoint Compliance Policy

  • Network Access Policy

  • Authentication Policy

  • Portal Policy

UX/Policy enhancement backend

Logical Network / Policy enhancements

HSTS default enabling (838556)

HSTS for the Admin GUI is enabled by default in versions 9.4.5+, 7.2.4+, and 7.4.0+.

What's new in FortiNAC F 7.2.0

What's new in FortiNAC F 7.2.0

FortiNAC software re-versioning

FortiNAC software re-versions to F 7.2 to match the Fortinet fabric. The label “F” in F 7.2 is added to indicate that this is Fortinet Fabric versioning, distinct from the FortiNAC 7.2 that was previously released.

Infrastructure upgrades

An infrastructure change has been made and a new product offering is available for the FortiNAC solution. The new FortiNAC appliances are being labeled FortiNAC-F.

  • New SKU

    FortiNAC Control and Application eXtended VM (SKU FNC-CAX-VM) is the continuation and extension of the FortiNAC Control and Application VM, supporting FortiNAC version F 7.2.

    FortiNAC Manager eXtended VM (SKU FNC-MX-VM) is the continuation and extension of the FortiNAC Manager VM, supporting FortiNAC F 7.2.

  • New operating system: CentOS is replaced with a FortiOS-like OS (FortiNAC-OS)

    The previous CentOS 7 Operating System is replaced with a custom Linux image with a CLI similar to that of FortiOS. It is called FortiNAC-OS in the documentation.

    FortiNAC-OS is implemented as a firmware image, similar to other Fortinet products (i.e. FortiGate).

    MySQL is replaced with MariaDB.

  • An appliance migration is required to move an existing system on CentOS to the new FNC-CAX or FNC-MX system.

  • Software Compatibility

FortiNAC Products

Description

Operating System

Version 8.x

Version 9.x

Version F7.2

Name: FortiNAC-Control-and-Application-VM

SKU: FNC-CA-VM

FortiNAC Control and Application

Virtual Server

CentOS

Yes

Yes

Yes

Name: FortiNAC-Manager-VM

SKU: FNC-M-VM

FortiNAC Manager Virtual Server

CentOS

Yes

Yes

Yes

Name: FortiNAC-CA-500C

SKU: FNC-CA-500C

Name: FortiNAC-CA-600C

SKU: FNC-CA-600C

Name: FortiNAC-CA-700C

SKU: FNC-CA-700C

FortiNAC 500C/600C/700C, Network Control and Application Server with RAID and Redundant Power Supplies

CentOS

Yes

Yes

Yes

Name: FortiNAC-M-550C

SKU: FNC-M-550C

FortiNAC Manager 550 Server Server with RAID and Redundant Power Supplies

CentOS

Yes

Yes

Yes

FortiNAC-F Products

Description

Operating System

Version 8.x

Version 9.x

Version F7.2

Name: FortiNAC-Control-and-Application-eXtended-VM

SKU: FNC-CAX-VM

FortiNAC Control and Application

next-gen Virtual Server

FortiNAC-OS

No

No

Yes

Name: FortiNAC-Manager-eXtended-VM

SKU: FNC-MX-VM

FortiNAC Manager next-gen Virtual Server

FortiNAC-OS

No

No

Yes

Name: FortiNAC-CA-500F SKU: FNC-CA-500F FortiNAC Network Control and Application Server (F Series) FortiNAC-OS No No vF7.2.3 and greater
Name: FortiNAC-CA-600F SKU: FNC-CA-600F FortiNAC High Performance Network Control and Application Server (F Series) FortiNAC-OS No No vF7.2.3 and greater
Name: FortiNAC-CA-700F SKU: FNC-CA-700F FortiNAC Ultra High Performance Network Control and Application Server (F Series) FortiNAC-OS No No vF7.2.3 and greater
Name: FortiNAC-M-550F SKU: FNC-M-550F FortiNAC Network Manager (F Series) FortiNAC-OS No No vF7.2.3 and greater

SAML/Shibboleth support with FortiNAC-OS no longer available

Due to vulnerabilities, FortiNAC-OS does not currently support SAML/Shibboleth. Support is scheduled to be added in a future release.

FortiNAC AWS secure deployment in cloud

FortiNAC F 7.2 changes its onboarding process to integrate with AWS to set up SSH keys during image deployment. The FortiNAC appliance is now cloud-aware and will identify the cloud it is running on during boot, read any provided metadata from the cloud, and initialize accordingly.

Cloud-init functionality with FortiNAC-OS

FortiNAC F 7.2 adds the ability to bootstrap the initial configuration of the FortiNAC Virtual Machines, compatible with AWS, KVM, ESX, and Hyper-V VMs.

As part of "cloud-init," the user can run CLI commands to set the access credentials.

For more information, see the updated deployment guide for the appropriate appliance.

MAC OSX Agents

MAC OSX Agents updated to be natively compatible with M1 processor.

Report enforced and non-enforced ports

Added ability to report both enforced and non-enforced ports and AP's/SSID's

New Visualization added to the Network Device Summary dashboard tile, as well as Network Inventory.

Device Support

New Device Integration for Cambium cnPilot series of AP

SNMP MAC-Notification trap support for Dell EMC Networking N3248P-ON Ver 6.7+

Support for Extreme Campus Controller E3120

UI/UX/Workflow enhancements

FortiGate VDOM modeling enhancements

UI changes to policy creation

Policy and Logical Networks views are upgraded to the new UI, adding a common table search/filtering/drag-and-drop. The following views have been changed:

  • Supplicant EasyConnect

  • Endpoint Compliance Policy

  • Network Access Policy

  • Authentication Policy

  • Portal Policy

UX/Policy enhancement backend

Logical Network / Policy enhancements

HSTS default enabling (838556)

HSTS for the Admin GUI is enabled by default in versions 9.4.5+, 7.2.4+, and 7.4.0+.