Considerations
-
Automated Captive Portal Detection: Devices that sense captive networks may trigger browsers during initial connection. To avoid this, automated captive portal detection must be disabled for VPN connections in FortiNAC. Instructions provided in section Disable Captive Network Assistant.
-
Split Tunnels: Whether or not split tunnel (certain traffic doesn't go over tunnel) or full tunnel (all traffic goes over tunnel) is configured is dependent upon the customer requirements.
-
Portal re-direct browser behavior:
-
Full tunnel: Browser automatically redirects to the VPN portal.
-
Split tunnel:
-
Browser does not automatically redirect to the VPN portal.
-
If using the Dissolvable Agent (DA), it is recommended to disable split-tunneling. This ensures automatic browser redirect in order to download the agent.
-
-
-
FortiNAC validates endstation after the tunnel is established. In order to do that, initial access is restricted. Once confirmed, restricted access is lifted. In full tunnel implementations, there will be interruption on applications that are running prior to connecting.
-
-
Windows machines: Recommended to disable browser popups on managed machines. See Disable Windows Browser Popups in the Appendix.
-
Remote clients connecting to the network through a FortiNAC-managed VPN cannot be connected to a local network that is also being managed by FortiNAC within the same management domain.