For endpoint compliance monitors, a Persistent Agent is required to ensure continuous monitoring and enforcement of compliance policies. Additionally, a Custom Scan is needed to scan endpoints for vulnerabilities ensuring that the compliance policies are enforced.
If more than 20 hosts are seen connected on a single port simultaneously, the port becomes a threshold uplink. This means the system dynamically identifies it as an uplink port because it has exceeded the predefined threshold for the number of hosts.
FortiNAC obtains connecting MAC address information through MAC notification traps. MAC notification traps send host information when a host connects or disconnects, which eliminates the need for FortiNAC to perform active polling. This method is preferred for learning Layer 2 information efficiently.
The correct system group that will force at-risk hosts into the quarantine network, based on point of connection, is 'Forced Quarantine'. This is because quarantine procedures are specifically designed to isolate at-risk or compromised systems from the rest of the network in order to prevent the spread of potential threats. Forced Remediation and Forced Isolation are related to corrective measures and containment, but they do not specifically imply moving the host into a quarantine network.
If a host remains stuck in the Registration VLAN during the on-boarding process, two possible reasons are: the wrong agent installed on the host or another unregistered host present on the same port. The wrong agent might not allow proper communication with the system, preventing the host from being properly registered and moved out of the Registration VLAN. Additionally, if there is another unregistered host on the same port, it could cause network conflicts that prevent the registered host from transitioning to the appropriate VLAN.