Fortinet black logo

Control Manager

Settings

Settings

The Settings View provides access to global system configuration options.

The Settings View is navigated using the tree control on the left side. The top level of the hierarchy represents the general configuration area, such as Authentication or System Communication. These areas are used to group similar functions. When a top level option such as System Communication is selected, the panel on the right contains a list of links to options that can be configured. For example, if System Communication is selected, the links provided include: Email Settings, Log Receivers, Mobile Providers, Proxy Settings, and SNMP. These options are also displayed below System Communication in the tree.

Use the Flat View button above the tree to list all of the options in alphabetical order instead of grouped in folders. Use the + Expand All and - Collapse All buttons at the top of the tree to open and close all of the folders. Click on the + symbol next to a folder to open it. Click on the - symbol to close the folder. Click on an option to display the corresponding configuration panel on the right.

Option

Description

Authentication

LDAP

Configure the connection with one or more LDAP directories for user authentication. See Authentication directories and Directory configuration.

Identification

Device Types

Manage device types that are used in Vendor OUIs, Hosts (registered as devices), Device Profiling Rules, and Pingable Devices. Both system and custom device types are displayed.

See Device types.

Vendor OUIs

Allows you to modify the Vendor OUI database, which is used to determine whether or not a MAC address is valid or by Device Profiler to profile devices by OUI. The database is updated periodically through the Auto Definition update process. See Vendor OUIs.

Network Control Manager

Server Synchronization

Create a list of MAC addresses that will be ignored when they connect to the network.

See Server synchronization

Security

Certificate Management

Manage, view, and install certificates with different encoding schemes and file formats.

See Certificate management.

System Communication

Email Settings

Enter settings for your email server. This allows FortiNAC to send email to Administrators and network users. See Email settings.

Log Receivers

Configure a list of servers to receive event and alarm messages from FortiNAC. See Log receivers.

Mobile Providers

Displays the default set of Mobile Providers included in the database. FortiNAC uses the Mobile Providers list to send SMS messages to guests and administrators . The list can be modified as needed. See Mobile providers.

SNMP

Set the SNMP protocol for devices that query FortiNAC for information. It is also used to set the SNMP protocol to accept SNMPv3 traps that register hosts and users. See SNMP and Register hosts and users with SNMPv3 traps.

System Management

Database Archive

Set the age time for archived data files and configure the schedule for the Archive and Purge task.

See Database archive.

Database Backup/Restore

Schedule database backups, configure how many days to store local backups, and restore a database backup. Note that this restores backups on the FortiNAC server, not backups on a remote server.

See Database backup/restore.

License Management

View or modify the license key for this server or an associated Application server.

See License management.

High Availability

Configuration for Primary and Secondary appliances for High Availability. Saving changes to these settings restarts both the Primary and Secondary servers.

See High availability.

NTP And Time Zone

Reset the time zone and NTP server for your FortiNAC appliances. Typically the time zone and NTP server are configured using the Configuration Wizard during the initial appliance set up. Requires a server restart to take effect.

See NTP and time zone.

Power Management

Reboot or power off the FortiNAC server. In the case of a FortiNAC Control Server / Application Server pair, reboot or power off each server individually.

See Power management.

Remote Backup Configuration

Configure Scheduled Backups to use a remote server via FTP and/or SSH.

See Configure the remote backup destination.

System Backups

Create a backup of all system files that are used to configure FortiNAC.

See System backups.

Updates

Agent Packages

Displays a list of the Dissolvable, Persistent and Passive Agent versions available on your FortiNAC appliance. Download new agents and add them to FortiNAC as they become available from Fortinet using the Download button. Download an Administrative template for GPO configuration to your PC from the FortiNACappliance using the links at the top of the view.

See Agent packages.

Operating System

Use Operating System Updates to download and install updates to the operating system on FortiNAC Control Manager.

See Operating system updates.

System

Use System Updates to configure download settings, download updates from Fortinet, install updates and view the updates log.

See System update.

Settings

The Settings View provides access to global system configuration options.

The Settings View is navigated using the tree control on the left side. The top level of the hierarchy represents the general configuration area, such as Authentication or System Communication. These areas are used to group similar functions. When a top level option such as System Communication is selected, the panel on the right contains a list of links to options that can be configured. For example, if System Communication is selected, the links provided include: Email Settings, Log Receivers, Mobile Providers, Proxy Settings, and SNMP. These options are also displayed below System Communication in the tree.

Use the Flat View button above the tree to list all of the options in alphabetical order instead of grouped in folders. Use the + Expand All and - Collapse All buttons at the top of the tree to open and close all of the folders. Click on the + symbol next to a folder to open it. Click on the - symbol to close the folder. Click on an option to display the corresponding configuration panel on the right.

Option

Description

Authentication

LDAP

Configure the connection with one or more LDAP directories for user authentication. See Authentication directories and Directory configuration.

Identification

Device Types

Manage device types that are used in Vendor OUIs, Hosts (registered as devices), Device Profiling Rules, and Pingable Devices. Both system and custom device types are displayed.

See Device types.

Vendor OUIs

Allows you to modify the Vendor OUI database, which is used to determine whether or not a MAC address is valid or by Device Profiler to profile devices by OUI. The database is updated periodically through the Auto Definition update process. See Vendor OUIs.

Network Control Manager

Server Synchronization

Create a list of MAC addresses that will be ignored when they connect to the network.

See Server synchronization

Security

Certificate Management

Manage, view, and install certificates with different encoding schemes and file formats.

See Certificate management.

System Communication

Email Settings

Enter settings for your email server. This allows FortiNAC to send email to Administrators and network users. See Email settings.

Log Receivers

Configure a list of servers to receive event and alarm messages from FortiNAC. See Log receivers.

Mobile Providers

Displays the default set of Mobile Providers included in the database. FortiNAC uses the Mobile Providers list to send SMS messages to guests and administrators . The list can be modified as needed. See Mobile providers.

SNMP

Set the SNMP protocol for devices that query FortiNAC for information. It is also used to set the SNMP protocol to accept SNMPv3 traps that register hosts and users. See SNMP and Register hosts and users with SNMPv3 traps.

System Management

Database Archive

Set the age time for archived data files and configure the schedule for the Archive and Purge task.

See Database archive.

Database Backup/Restore

Schedule database backups, configure how many days to store local backups, and restore a database backup. Note that this restores backups on the FortiNAC server, not backups on a remote server.

See Database backup/restore.

License Management

View or modify the license key for this server or an associated Application server.

See License management.

High Availability

Configuration for Primary and Secondary appliances for High Availability. Saving changes to these settings restarts both the Primary and Secondary servers.

See High availability.

NTP And Time Zone

Reset the time zone and NTP server for your FortiNAC appliances. Typically the time zone and NTP server are configured using the Configuration Wizard during the initial appliance set up. Requires a server restart to take effect.

See NTP and time zone.

Power Management

Reboot or power off the FortiNAC server. In the case of a FortiNAC Control Server / Application Server pair, reboot or power off each server individually.

See Power management.

Remote Backup Configuration

Configure Scheduled Backups to use a remote server via FTP and/or SSH.

See Configure the remote backup destination.

System Backups

Create a backup of all system files that are used to configure FortiNAC.

See System backups.

Updates

Agent Packages

Displays a list of the Dissolvable, Persistent and Passive Agent versions available on your FortiNAC appliance. Download new agents and add them to FortiNAC as they become available from Fortinet using the Download button. Download an Administrative template for GPO configuration to your PC from the FortiNACappliance using the links at the top of the view.

See Agent packages.

Operating System

Use Operating System Updates to download and install updates to the operating system on FortiNAC Control Manager.

See Operating system updates.

System

Use System Updates to configure download settings, download updates from Fortinet, install updates and view the updates log.

See System update.