Listing Thumbnail

    FortiNAC Secure Network Access Control - BYOL

     Info
    Deployed on AWS
    FortiNAC is a zero-trust access solution that oversees and protects all digital assets connected to the enterprise network, covering devices ranging from IT, IoT, OT/ICS, to IoMT. With network access control that enhances the Fortinet Security Fabric, FortiNAC delivers visibility, control, and automated response for everything that connects to the network. FortiNAC provides protection against IoT threats, extends control to third-party network devices, and orchestrates automatic response to a wide range of network events.
    4.4

    Overview

    Visibility, Zero Trust Access, and Incident Response for Connected Assets and Users FortiNAC™ continues to be a cutting-edge network access control solution, enabling organizations to enforce network access policies and assure adherence to security protocols in light of increasingly sophisticated threats. It provides a comprehensive snapshot of all devices and users on the network, facilitating granular control of access based on user roles, device types, network locations, and now the behavioral patterns of devices and users. The solution's capability now extends beyond automated onboarding of new endpoints; it incorporates real-time threat intelligence and continuous risk assessment of devices, leveraging machine learning and AI technologies from FortiGuard Services. Given the rising prominence of BYOD (Bring Your Own Device) and IoT (Internet of Things), FortiNAC's continuous monitoring and immediate remediation of non-compliant devices have become even more crucial. Moreover, FortiNAC's integration goes beyond third-party security solutions; it integrates with a wide range of cloud-based platforms and DevOps tools to ensure seamless and secure network operations in hybrid IT environments. FortiNAC leverages its integration with FortiAnalyzer to gain deep insight into network security posture, encompassing realtime visibility, predictive analytics, and more robust compliance reporting. With FortiNAC, organizations can more effectively secure their network against unauthorized access, potential threats, and increasingly, the insider threats, aligning with the emerging Zero Trust security model that emphasizes "never trust, always verify".

    Highlights

    • Granular Visibility Across the Network for Every Device and User, the FortiNAC leverages AI and machine learning from FortiGuard Security Services to provide detailed profiling of devices, including headless devices and IoT assets on your network. This profiling incorporates multiple information sources, behavior patterns, and real-time threat intelligence to accurately identify and assess what is on your network.
    • Seamless Integration and Control Across Diverse Environments, with the power of micro-segmentation and Zero Trust policies, FortiNAC allows for configuration changes on switches and wireless products from an extended range of vendors. It amplifies the reach of the Security Fabric across multi-cloud, hybrid IT, and heterogeneous environments, implementing "never trust, always verify" principles.
    • Automated Responsiveness, the FortiNAC reacts to network events in real-time to contain threats before they spread, utilizing a broad and customizable set of automation policies. Leveraging AI, these policies can instantly trigger configuration changes and remediation actions when targeted behavior or anomalies are observed, aligning with the Zero Trust model's dynamic and proactive approach.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 7.6.7

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    FortiNAC Secure Network Access Control - BYOL

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Please bring your own license

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    FortiNAC support for RADIUS-only devices

    RADIUS-only device support is introduced with a new selector-based architecture that eliminates SNMP dependencies and enables cloud-managed device support. It also provides scalable configuration through reusable objects and rule-based selectors.

    See the Support for RADIUS-only Devices Reference Manual.

    Support for sending remote groups to FortiGate

    Support for sending remote group information from FortiNAC to FortiGate and Palo Alto Networks firewalls is introduced. This enables seamless integration of user and host group management within firewall security policies through dynamic tagging.

    See the Remote Group Integration Guide.

    ATI IPv6 support

    This release introduces comprehensive IPv6 support across all major platform components and enables full end-to-end IPv6 communication with the Portal and Agents and Admin UI. Key enhancements include RADIUS and EAP authentication and 802.1X support over IPv6. The release also improves device discovery and polling for IPv6-enabled network devices.

    See IPv6 Support F 7.6.7 in the Administration Guide.

    IP-MAC mapping enhancements

    This release introduces IP-MAC mapping enhancements designed to reduce L3 polling overhead while maintaining or improving mapping accuracy. Cache IP-MAC Mapping from DHCP uses DHCP fingerprint data as an alternative ARP source. RADIUS Framed-IP-Address caching uses Accounting attributes for real-time IP assignment tracking. VLAN-Subnet Mapping improves IP identification in complex topologies. L3 Polling Fallback retrieves ARP entries from uplink devices when target devices do not support L3 polling.

    See Cache IP-MAC Mapping from DHCP in the Administration Guide.

    Removal of the SNMP requirement for Meraki Switch and WAP integration

    This release introduces a redesigned Meraki Service Connector with API-based polling from Meraki Cloud and automatic device discovery without manual device addition. The connector supports multiple Meraki organizations through a single service connector. It also supports optional SNMP credentials and Configuration Selectors and tag-based filtering and RADIUS-only operation.

    See the Meraki Service Connector documentation.

    FortiAI Assistant

    FortiAI NAC Assist Integration introduces an AI-powered chat assistant within the FortiNAC Central Access web interface. Administrators can interact with their network using natural language queries to quickly access information about devices and users and compliance status and security events. This feature simplifies common administrative tasks while maintaining strict security controls and data privacy within the FortiNAC infrastructure.

    See FortiAI NAC Assist in the Administration Guide.

    FortiNAC Live Logs in the GUI

    A new real-time authentication logging interface in the GUI displays detailed information for LDAP and Local and RADIUS and SAML and Social authentication methods. This enables administrators to troubleshoot issues as they occur.

    See Authentication Logs in the Administration Guide.

    FortiNAC CA clustering failover health check mechanism

    A comprehensive five-layer health check mechanism is introduced with configurable intervals and thresholds. It includes integrated failover capabilities for both 1+1 and N+1 HA configurations as well as detailed CLI and GUI configuration options for monitoring infrastructure and database and cache and services and custom components.

    See the CLI Reference Manual.

    MDM and Service Connector columns for the Host page and User/Host Profile

    Device visibility and filtering are enhanced by adding detailed MDM and OT service connector information to the Host page and User/Host Profile matching criteria. Administrators can identify which service connector manages each device.

    See Hosts Settings in the Administration Guide.

    FortiNAC support within OCI DRCC Oman

    This release adds support for deploying FortiNAC virtual appliances in Oracle Cloud Infrastructure DRCC Oman using Marketplace images.

    Improved handling of user and machine authentication scenarios for Logged On User

    The authentication handling mechanism now checks previous user authentication states before clearing the Logged On User field during machine authentication. This ensures accurate user tracking across different authentication scenarios.

    Automatic shutdown of unused or disabled services

    An automated Captive Portal service shutdown feature optimizes system resources by automatically stopping unused services such as dhcpd and named and apache2 httpd while maintaining the correct service dependency order during startup and shutdown.

    See the Machine Authentication Guide.

    Perpetual license expiration display

    Perpetual licenses now display never expired instead of 0 days. The GUI and CLI also provide a clearer distinction between perpetual and subscription licenses.

    Admin audit and event logging

    This release adds admin audit and event logging for port enforcement changes and data exports and syslog forwarding to improve security visibility and compliance monitoring.

    See the CLI Reference Manual.

    Additional data sent to FortiAnalyzer

    FortiNAC now sends additional endpoint and network data to FortiAnalyzer to support new auditing and compliance reports. Syslog messages sent to FortiAnalyzer receivers now include the Hostname field to improve event-source identification and troubleshooting.

    See the FortiAnalyzer Device Integration Guide.

    FortiNAC-M Shared IP support in public cloud environments

    This release introduces cloud-native Shared IP support through a new leader health check API. The API enables external load balancers such as Azure Load Balancer to determine which cluster node is the current leader and route traffic appropriately. This feature simplifies management and enhances availability and improves security compliance for customers deploying FortiNAC Manager clusters in cloud environments.

    See the Manager Cluster Guide.

    Regex support on the OUI configuration page for randomized MAC addresses

    This release introduces enhanced regex support for vendor code validation. Administrators can define custom regular expressions for more flexible device identification beyond traditional OUI matching. The feature improves handling of randomized MAC addresses used by modern privacy-focused devices and includes specialized aging policies for regex-matched hosts. The update also includes GUI and API and logging enhancements for regex pattern management.

    See Aging in the Administration Guide.

    Interface enable and disable controls with port speed and duplex settings

    This release adds interface configuration capabilities through the CLI. Administrators can enable or disable network interfaces and configure port speed and duplex settings. This enhancement provides dynamic network management without requiring physical device access.

    See the CLI Reference Manual.

    Configurable RadSec idle timeout

    A new RadSec Idle Timeout setting allows administrators to define how long RADIUS over TLS connections remain open when no activity is detected. The default value is 60 seconds and the configurable range is 60 to 600 seconds. This enhancement improves the resilience of TLS-secured RADIUS sessions by allowing administrators to match idle lifetimes to site-specific conditions. It reduces unnecessary reconnects and session churn.

    See RadSec Idle Timeout Configuration under Configure Local Radius Server Settings in the Administration Guide.

    Guest and contractor reauthentication time

    A new re-registration period feature allows administrators to configure how frequently guest and contractor hosts must re-register to maintain network access. The configurable re-registration period in Guest and Contractor templates replaces the previous reauthentication period and supports values from 1 to 8760 hours. When the re-registration period expires the registered hosts are deleted and marked as rogue. Users must then re-enter their credentials to regain access.

    See Guest Contractor Users and Guest Contractor Templates in the Administration Guide.

    Device integrations

    Added support for H3C Wireless Controller WX3820X.

    Added support for D-Link Switch DIS-300G-14PSW.

    Added support for Aruba JL255A 2930F-24G-PoE+-4SFP+.

    Added support for Barox Switch LT-PITE-402GBTME.

    Added support for mapping the Cisco 8300 router to a MIB file.

    Added integration with Transition and Lantronix switches.

    Added support for Altai standalone APs.

    Additional details

    Usage instructions

    After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiNAC. Connect to the secured Web UI via the public DNS address: https://<public DNS address>:8443. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and empty password. You can reference the FortiNAC-VM AWS admin guide is located at: https://docs.fortinet.com/document/fortinac-f/7.6.0/aws-deployment-guide/351237/overview#_Toc178942360 

    Support

    Vendor support

    This is a Bring Your Own License model, before to request your instance please make sure you have the FortiNAC licensing order processed by Fortinet sales. When you have the registration steps completed, you'll receive a timely response to any technical issues as well as complete visibility on the ticket resolution progress. FortiCare Support Services include firmware upgrades, Support portal access, and associated technical resources. FortiGuard Security Services include up-to-the minute threat intelligence delivered in real time to stop the latest threats.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.4
    20 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    55%
    45%
    0%
    0%
    0%
    0 AWS reviews
    |
    20 external reviews
    External reviews are from G2 .
    Telecommunications

    Must Have Tool for All size of Companies

    Reviewed on Apr 10, 2024
    Review provided by G2
    What do you like best about the product?
    Excellent user experience. By implementing FortiNAC you will have good control over the clients and the tool is easy to implement.
    What do you dislike about the product?
    Integration requirements are challenging.
    What problems is the product solving and how is that benefiting you?
    You can manage the devices connected to your network and maintain a comprehensive overview of the devices. By applying compliance policies, clients that pass these policies will be permitted to connect, ensuring a secure network environment
    Vikash D.

    A Robust Solution for Enhanced Network Security and Access Control

    Reviewed on Jan 28, 2024
    Review provided by G2
    What do you like best about the product?
    FortiNAC excels in providing comprehensive network security and access control. Its robust features, seamless integration, and user-friendly interface make it an effective solution for safeguarding networks and managing access efficiently.
    What do you dislike about the product?
    Limited customization options and occasional interface complexities can be challenging. Improved flexibility and a more intuitive interface could enhance the overall user experience.
    What problems is the product solving and how is that benefiting you?
    FortiNAC addresses security challenges by enforcing robust access controls, identifying and responding to network threats. It enhances overall security posture, mitigates risks, and ensures a resilient network environment, providing peace of mind.
    Abrar Ahmad M.

    Streamlining Network Security

    Reviewed on Jan 17, 2024
    Review provided by G2
    What do you like best about the product?
    Every Network Architect need a device which is scalable for small and big enterprise.

    FortiNAC is the good choice. As it can handle a large number of devices and diverse network environments. Also, helps in identifying and responding to threats in real-time.
    What do you dislike about the product?
    Cost consideration: The cost will be concern for smaller organization or those on a tight budget.
    What problems is the product solving and how is that benefiting you?
    Provides administrators with visibility into the devices connected to the network, compliance status, and other relevant information. Which helps in monitoring and analyzing network access patterns
    Research

    It was easy, reliable and smooth experience.

    Reviewed on Jan 17, 2024
    Review provided by G2
    What do you like best about the product?
    It gives you more control with extended approach.
    What do you dislike about the product?
    Nothing was bad in my experience, keep up the good work.
    What problems is the product solving and how is that benefiting you?
    It is helping in extended third party network control
    Sophia W.

    "An amazing network security platform."

    Reviewed on Oct 17, 2023
    Review provided by G2
    What do you like best about the product?
    It is one of the most advanced network security platform that handles all the work very efficiently and provides you with an amazing layer of protection to save you from modernized cybercrimes. Moreover, the implementation process is easier as compared to others and provide with real time management properties and can handle malware and identified threats in its own.
    What do you dislike about the product?
    Even though it has real time management tools that are very handy it does not have an advanced analysis and monitoring service which does not give you an in-depth insight of the operation handling on the website.
    What problems is the product solving and how is that benefiting you?
    It is an amazing network security platform that not only saves and adds a layer of protection on the networking of an organization but also manages indented threats on its own and restrict other unknown threats that may be harmful for the networking.
    View all reviews