- Click System > Settings.
- Expand the System Communication folder.
- Select Addresses from the tree.
This view provides a list of address objects and address group objects that can be created and modified with your desired address scopes. Address objects can be created by subnet or by IP Range, then combined into address groups. Address groups can be selected within the SSO and VPN configurations of the virtualized devices configuration view. See Virtualized Devices.
Address objects and address group objects are used to determine which FortiGate should receive SSO messages from hosts connecting to the network. Group objects allow for control over the network ranges and scopes used to filter SSO messages to each FortiGate.
Previous versions of FortiNAC automatically created forwarding tables from interface addresses that existed on each FortiGate using these rules:
Note: The above two rules could be overridden for individual FGTs by the use of a FNAC device model attribute named ForceSSO. When added to a FGT model and set to true, it would indicate that the FGT should receive all SSO messages without any IP interface filtering.
The first time each FortiGate is accessed by FortiNAC, as the system starts, FortiNAC will automatically populate the address and address group tables using the same process in previous versions of FortiNAC. In order to expand the scope of FortiGates to which SSO messages should be sent for those direct connections, an option can be configured. This can be done with the command (run from the FNAC command shell):
These objects can then be utilized or modified to the user's preferences.
Note that addresses are only read from FortiGates that have Fabric Connectors configured for FortiNAC. If no such Fabric Connectors exist, no addresses will be read and created. This is only done once for each FortiGate, so once the addresses are created for a FortiGate, changes to that FortiGate do not affect changes to the existing address objects. All changes to the address objects after they are initialized must be made manually.