What is our primary use case?
We installed Fortinet FortiNAC in a large company in a VM environment. They have a lot of end-users and complex user account needs. For example, some of the VIPs and different guests all need different access permissions and some of them are connected through the Active Directory credentials which we have to have a portal page for them to gain access.
Another layer of complexity is different users are receiving accounts from many departments. For example, the customer's IT department gives them access and they send the credentials to the guest by email. The IT department can limit their account in different ways, such as only allowing the account access for a period of time.
What is most valuable?
Fortinet FortiNAC has good user account customization.
We can change the logo for the portals to meet the customer's needs. The portal default language is English but it supports all languages, such as Turkish. The portal can be optimized very easily.
Device profiling is a good feature, we can block devices, such as iOS or Android.
Endpoint compliance is a great feature that allows us to restrict and quarantine devices. For example, if a device is not using the latest version of an operating system or antivirus program we can detect it and prohibit their access. If certain conditions are met with the customer's policies, we can let them have access. Otherwise, our endpoints compliance rules block or quarantine their devices on the network.
What needs improvement?
Integration is hard in Fortinet FortiNAC, but they are evolving and getting better. For example, with Cisco, Aruba, Huawei, and Extreme devices, Fortinet FortiNAC is working properly, but some other devices have problems.
For how long have I used the solution?
I have been using Fortinet FortiNAC for a couple of months.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
Fortinet FortiNAC can extend your existing network. For example, if you have to put another switch, access point, or another networking device to complete the site we can with one or two clicks add these devices and the same rules and policies. It is highly scalable and can extend your infrastructure.
We currently have two customers using Fortinet FortiNAC
How was the initial setup?
The installation is not straightforward, it can be hard. The documentation should be better in explaining to process in more detail. The installation requires too much experience and knowledge about network infrastructure. It's not easy, you have to be an expert.
The difficulty level of the installation and time depends on many factors. For example, one of our customer's installations was simple because they only had to block one site and only had one hardware vendor, such as Cisco.
Our second installation was more difficult because the customer had many different hardware vendors, such as Cisco, Huawei, Aruba, and Extreme as part of their infrastructure. This requires configuring different settings on every device, it can be complicated. This can take a lot of time.
What about the implementation team?
We do the implementation and the amount of staff needed depends on the size of the infrastructure and hardware vendors involved. If it is a smaller environment with a single vendor then the process could take two to three days.
If the customer size is very large and they are using the different sites and cities, and many different network infrastructures, the implementation would take time and you would have to manage everything well. When you have a complex network, it can take approximately15 days to implement. The number of vendors they're working with can increase the implementation time duration. If companies only have one vendor, it's easy, but two or three different vendor integration is a little bit harder and takes time.
Customer's needs are very important, because some customers, only want that 1x configuration. However, other customers want 1x configuration, custom portal pages, and many endpoint compliance rules. The more features the more time it will take.
What's my experience with pricing, setup cost, and licensing?
The price of the license required is based on how many users are going to be using the solution. If you want more users you can upgrade your license.
Which other solutions did I evaluate?
I have evaluated other NAC solutions.
What other advice do I have?
I would recommend Fortinet FortiNAC to others because we did evaluate other NAC solutions and this solution is very good compared to the others. The best benefit of Fortinet FortiNAC is the stability and it can work with other vendors. Some NAC products only work with their products and do not support other vendors.
The major benefit I have found is that this solution can work with other products. A customer typically has more than one vendor, such as access points, printers, and other network products. A lot of the other vendors only are working with their products. It's very important for me that Fortinet FortiNAC can work with the other vendors properly and can integrate easily. When I check the Fortinet website, it shows every vendor's details with an explanation about the integration of the Fortinet FortiNAC. For example, you can find out how to integrate the Fortinet FortiNAC with the Cisco wireless controller. I can find the documents, turn to the pages and find all the information I need. I can find it very easily.
I rate Fortinet FortiNAC a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner