Monitoring endpoints Endpoint NAC
FortiGate Version 4.0 MR1 Administration Guide
700 01-410-89802-20090903
http://docs.fortinet.com/ • Feedback
Figure 435: Creating Endpoint NAC profiles
Monitoring endpoints
To view the list of known endpoints, go to Endpoint NAC > Endpoints. An endpoint is
added to the list when it uses a firewall policy that has Endpoint NAC enabled.
Profile list
Create New Create a new Endpoint NAC profile.
Name The name of the Endpoint NAC profile.
FortiClient Enforcement Green check mark icon - enabled.
Grey X icon - not enabled.
Application Detection List The application detection list specified in this profile.
Delete Delete this profile.
Edit Edit this profile.
Endpoint NAC Profile settings
Name Enter a name for the Endpoint NAC profile.
For non-compliant hosts: Enable one of the following options:
Notify hosts to install
FortiClient (warn only)
Allow users to continue browsing without installing
FortiClient Endpoint Security.
Quarantine hosts to user
portal (enforce compliance)
Keep endpoint quarantined until user installs FortiClient
Endpoint Security.
Additional Client Options Enable to enforce any of the following:
Anti-virus Enabled Require that the antivirus feature is enabled.
Anti-virus Up-to-date Require that the antivirus signatures are up-to-date.
Firewall Enabled Require that the firewall feature is enabled.
Enable Application Detection Enable to check applications on the endpoint against an
application detection list.
Application Detection List Select the application detection list to use.