Fortinet black logo
7.2.0

Model Configuration

Model Configuration

  1. Login to the FortiNAC Administration UI and navigate to Network > Inventory.

  2. Click on the newly added model and click the Model Configuration tab.

  3. Fill in the fields as appropriate:

    RADIUS Mode

    Proxy (default)

    RADIUS Primary Server

    Applies to 802.1x authentication only: Either the default RADIUS server or a pre-configured RADIUS server must be selected. RADIUS servers are configured on the RADIUS Settings window.

    RADIUS Secondary Server

    Applies to 802.1x authentication only: Either the default RADIUS server or a pre-configured RADIUS server must be selected. RADIUS servers are configured on the RADIUS Settings window.

    RADIUS Shared Secret

    Required for both MAC and 802.1x authentication. Must match the value entered on the device itself and the value entered on the RADIUS settings window.

  4. Click the Read VLANs button. This populates the drop-down lists for the different connection states, such as Registration. Data in the drop-down lists represents the VLANs created on the device.

  5. Select a setting in Access Enforcement for each host state.

  6. In the Access Value column select a VLAN for each host state desired to enforce.

  7. In the Preferred Container field, select the Container in Topology which the Wireless Access Points should be placed as they are discovered.

  8. Click Save.

  9. Click Polling tab.

  10. Enter the appropriate L2 (Hosts) Polling value (minutes) based on the chart below. For best performance, it is recommended not to go lower than the specified value.

    Example:

    Total number of Access Points modeled in Topology: 800

    Acceptable values: 15, 20, 30, 60

    Not recommended: 10, 5

    Total Number of Access Points

    Recommended Lowest Value

    700 and below

    10 minutes

    800

    15 minutes

    1000

    20 minutes

    2000

    30 minutes

    2500

    60 minutes

Model Configuration

  1. Login to the FortiNAC Administration UI and navigate to Network > Inventory.

  2. Click on the newly added model and click the Model Configuration tab.

  3. Fill in the fields as appropriate:

    RADIUS Mode

    Proxy (default)

    RADIUS Primary Server

    Applies to 802.1x authentication only: Either the default RADIUS server or a pre-configured RADIUS server must be selected. RADIUS servers are configured on the RADIUS Settings window.

    RADIUS Secondary Server

    Applies to 802.1x authentication only: Either the default RADIUS server or a pre-configured RADIUS server must be selected. RADIUS servers are configured on the RADIUS Settings window.

    RADIUS Shared Secret

    Required for both MAC and 802.1x authentication. Must match the value entered on the device itself and the value entered on the RADIUS settings window.

  4. Click the Read VLANs button. This populates the drop-down lists for the different connection states, such as Registration. Data in the drop-down lists represents the VLANs created on the device.

  5. Select a setting in Access Enforcement for each host state.

  6. In the Access Value column select a VLAN for each host state desired to enforce.

  7. In the Preferred Container field, select the Container in Topology which the Wireless Access Points should be placed as they are discovered.

  8. Click Save.

  9. Click Polling tab.

  10. Enter the appropriate L2 (Hosts) Polling value (minutes) based on the chart below. For best performance, it is recommended not to go lower than the specified value.

    Example:

    Total number of Access Points modeled in Topology: 800

    Acceptable values: 15, 20, 30, 60

    Not recommended: 10, 5

    Total Number of Access Points

    Recommended Lowest Value

    700 and below

    10 minutes

    800

    15 minutes

    1000

    20 minutes

    2000

    30 minutes

    2500

    60 minutes