A FortiNAC-F port can belong to both Forced Registration and Forced Remediation system groups . These enforcement groups are not mutually exclusive and are not evaluated according to a ranking between the groups. Instead, FortiNAC-F determines the applicable enforcement according to the state of each host connected through that point of connection .
The Study Guide explicitly demonstrates overlapping enforcement membership: all Building 1 ports are members of Forced Registration , while second- and third-floor ports are additionally members of Forced Remediation .
FortiNAC-F then applies state-specific logic:
A rogue/unregistered host on the port satisfies Forced Registration and is moved to the Registration isolation network.
An at-risk host on the same port satisfies Forced Remediation and is moved to the Quarantine/Remediation isolation network.
The exhibit is particularly relevant because the highlighted port shows Multiple Hosts connected. Each host is evaluated independently according to its state, so different enforcement mechanisms can apply to different endpoints sharing that port.
Therefore, placing the port in both groups enables both types of enforcement , depending on the state of the connected hosts.
Study Guide Reference: State-Based Control → System Groups; Logic to Determine Isolation; Non-Normal Status Device Evaluation , pp. 212–214 .
Top of Form
Bottom of Form
Submit