Listing Thumbnail

    FortiNAC Secure Network Access Control - BYOL

     Info
    Deployed on AWS
    FortiNAC is a zero-trust access solution that oversees and protects all digital assets connected to the enterprise network, covering devices ranging from IT, IoT, OT/ICS, to IoMT. With network access control that enhances the Fortinet Security Fabric, FortiNAC delivers visibility, control, and automated response for everything that connects to the network. FortiNAC provides protection against IoT threats, extends control to third-party network devices, and orchestrates automatic response to a wide range of network events.

    Overview

    Visibility, Zero Trust Access, and Incident Response for Connected Assets and Users FortiNAC™ continues to be a cutting-edge network access control solution, enabling organizations to enforce network access policies and assure adherence to security protocols in light of increasingly sophisticated threats. It provides a comprehensive snapshot of all devices and users on the network, facilitating granular control of access based on user roles, device types, network locations, and now the behavioral patterns of devices and users. The solution's capability now extends beyond automated onboarding of new endpoints; it incorporates real-time threat intelligence and continuous risk assessment of devices, leveraging machine learning and AI technologies from FortiGuard Services. Given the rising prominence of BYOD (Bring Your Own Device) and IoT (Internet of Things), FortiNAC's continuous monitoring and immediate remediation of non-compliant devices have become even more crucial. Moreover, FortiNAC's integration goes beyond third-party security solutions; it integrates with a wide range of cloud-based platforms and DevOps tools to ensure seamless and secure network operations in hybrid IT environments. FortiNAC leverages its integration with FortiAnalyzer to gain deep insight into network security posture, encompassing realtime visibility, predictive analytics, and more robust compliance reporting. With FortiNAC, organizations can more effectively secure their network against unauthorized access, potential threats, and increasingly, the insider threats, aligning with the emerging Zero Trust security model that emphasizes "never trust, always verify".

    Highlights

    • Granular Visibility Across the Network for Every Device and User, the FortiNAC leverages AI and machine learning from FortiGuard Security Services to provide detailed profiling of devices, including headless devices and IoT assets on your network. This profiling incorporates multiple information sources, behavior patterns, and real-time threat intelligence to accurately identify and assess what is on your network.
    • Seamless Integration and Control Across Diverse Environments, with the power of micro-segmentation and Zero Trust policies, FortiNAC allows for configuration changes on switches and wireless products from an extended range of vendors. It amplifies the reach of the Security Fabric across multi-cloud, hybrid IT, and heterogeneous environments, implementing "never trust, always verify" principles.
    • Automated Responsiveness, the FortiNAC reacts to network events in real-time to contain threats before they spread, utilizing a broad and customizable set of automation policies. Leveraging AI, these policies can instantly trigger configuration changes and remediation actions when targeted behavior or anomalies are observed, aligning with the Zero Trust model's dynamic and proactive approach.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 7.6.3

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    FortiNAC Secure Network Access Control - BYOL

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Please bring your own license

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    FortiNAC to use Entra ID as native authentication source

    FortiNAC now supports username password/certification authentication from Microsoft Entra ID in RADIUS 802.1X and portal login. Username password authentication from Microsoft Entra ID in portal login is also supported. See the Microsoft Entra ID Authentication Guide.

    FortiNAC SAML SSO enhancements

    FortiNAC now supports comprehensive SAML 2.0 Single Sign-On (SSO) for both administrators and end users.

    • Admin SAML SSO enables login via external Identity Providers (IdPs) like Microsoft Entra ID, with support for role mapping, auto account creation, and high availability.
    • User SAML SSO allows end users to authenticate through the Captive Portal using IdP credentials, with group assignment based on SAML attributes.
    • A simplified FortiCloud SSO option is also available for admin login, requiring minimal setup using a preconfigured IdP. See the FortiNAC SAML SSO Guide.

    Armis integration

    An Armis service connector now allows FortiNAC to communicate with Armis Centrix, adding devices managed by Armis onto FortiNAC as hosts, along with relevant IP, MAC Address, and compliance level info. See the Armis Integration Guide.

    Secure Boot and File integrity verification

    Version F 7.6.3 also introduces a new security enhancement designed to protect the system from unauthorized modifications and ensure software authenticity across all platforms.

    • File Integrity Verification at Boot and Runtime: A defined set of boot-critical files are hashed and verified during boot.
    • Signed Firmware Enforcement: GA firmware images are now cryptographically signed with both Fortinet and external authority signatures.
    • Controlled Upgrade/Downgrade Paths: Systems running signed builds will block unsigned upgrades by default, ensuring a trusted upgrade path. Downgrade to pre-7.6.3 unsigned builds is still allowed if needed, with user confirmation.
    • No Lock-In or Upgrade Dead-Ends: Customers are not restricted or locked out of their systems.
    • Air-Gapped Environment Support: The integrity checks and signature verification are fully self-contained and function without internet access. The command can be accessed in CLI with: execute set-next-reboot

    EMS Cloud configuration

    FortiClient EMS Cloud is now supported in addition to the on-premise solution. See FortiClient EMS Integration for details.

    Link Aggregation Group (LAG) support on FortiNAC appliances

    FortiNAC now supports Link Aggregation, optimizing port usage by linking a group of ports together to form a single Link Aggregation Group (LAG). Aggregating ports multiplies the bandwidth between two devices, increases port flexibility, and provides link redundancy. See Aggregation and Redundancy in the CLI Reference Manual.

    Enhancements

    Automated certificate sync

    In a High Availability system, users can now configure certificates for the secondary server directly through the primary server's GUI, streamlining certificate management across the cluster.

    Improved failover time for High Availability Active-Stand-by Mode

    This feature reduces failover time from the primary to the secondary node by keeping services on the secondary running at all times. See the High Availability FortiNAC-OS Guide.

    Independent IP CA N+1 setup

    Version F 7.6.3 introduces command line configuration support for N+1 failover port 1 independent IP. When a primary is down and the secondary takes control, the secondary can be accessed by the independent IP. Each primary server has its own independent IP settings. See the N+1 High Availability Configurations in the CLI Reference Manual.

    NCM Cluster shared IP for FortiNAC manager

    This feature introduces a shared IP feature similar to legacy HA. It allows administrators to access any appliance using the same IP address, regardless of which is currently acting as the primary control server-providing a single point of access for managing the HA group.

    N+1 Health Check refinement

    Feature simplifies and enhances the custom health check process, removing "RADIUS" and "TCP echo" types and retaining only "ICMP" and "TCP (on specific port)." The Secondary CA now automatically performs a health check on the Primary CA before promotion, eliminating the need for gateway check logic. Additionally, a CLI interface is provided to adjust health check interval parameters for greater flexibility.

    Split Brain prevention

    HA pairs managed by a FortiNAC Manager are now less prone to split-brain scenarios, improving overall system stability and reliability. See the High Availability FortiNAC-OS Guide.

    Device Detection database with FortiGuard

    This enhancement expands the FortiNAC database by incorporating new device types aligned with FortiGuard Category/Subcategory mappings. Previously, FortiNAC supported only 27 device types, while FortiGuard offers over 120 subcategories. Now, improved integration with FortiGuard's IoT detection capabilities enables FortiNAC to support over 140 device types in total. See Device Types in the Administration Guide.

    Firmware upgrade enhancements

    Upgrading FortiNAC from the FortiGuard Distribution Network (FDN) allows the device to automatically fetch and install the latest recommended firmware directly from Fortinet, ensuring quick access to new feature with minimal manual effort. See Updates in the Administration Guide.

    TEAP enhancement

    FortiNAC now supports TEAP (Tunnel Extensible Authentication Protocol) multiple authentication types (inner methods) to be performed inside the tunnel such as username/password or certificates. It supports flexible combinations of user and machine authentication. See Authenticate Devices Using TEAP.

    Customize device attributes with output from Vulnerability Scanner

    Vulnerability Scanner has been added as a new Service Connector type. FortiNAC now supports integration with Tenable and Qualys vulnerability scanners. Once configured, additional device attributes from the scanner output are available in the Hosts and Vulnerability views under Users & Hosts. See Vulnerability Scanner in the Administration Guide.

    MS Intune integration now pulls in ownership information

    An enhancement to the MS Intune MDM Service Connector on the FortiNAC side adds the display of enrolled devices, ownership in the "Host Role" column in Users & Hosts > Hosts view.

    CLI Access via FortiNAC GUI

    Users can now access the FortiNAC CLI directly from the FortiNAC GUI, providing easier administrative access and improved usability. See CLI Console in the Administration Guide.

    Additional details

    Usage instructions

    After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiNAC. Connect to the secured Web UI via the public DNS address: https://<public DNS address>:8443. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and empty password. You can reference the FortiNAC-VM AWS admin guide is located at: https://docs.fortinet.com/document/fortinac-f/7.6.0/aws-deployment-guide/351237/overview#_Toc178942360 

    Support

    Vendor support

    This is a Bring Your Own License model, before to request your instance please make sure you have the FortiNAC licensing order processed by Fortinet sales. When you have the registration steps completed, you'll receive a timely response to any technical issues as well as complete visibility on the ticket resolution progress. FortiCare Support Services include firmware upgrades, Support portal access, and associated technical resources. FortiGuard Security Services include up-to-the minute threat intelligence delivered in real time to stop the latest threats.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.