New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE5_FNC_AD_7.6 Exam - Topic 3 Question 2 Discussion

Actual exam question for Fortinet's NSE5_FNC_AD_7.6 exam
Question #: 2
Topic #: 3
[All NSE5_FNC_AD_7.6 Questions]

A user was attempting to register their host through the registration captive portal. After successfully registering, the host remained in the registration VLAN. Which two conditions would cause this behavior? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: C, D

The process of moving a host from a Registration VLAN to a Production VLAN (Access VLAN) is a fundamental part of the FortiNAC-F 'VLAN steering' workflow. When a host successfully registers via the captive portal, FortiNAC-F evaluates its Network Access Policies to determine the correct VLAN. If the host remains stuck in the Registration VLAN despite a successful registration, it is typically due to port-level restrictions or the presence of other unregistered devices.

The two most common reasons for this behavior as per the documentation are:

The port default VLAN is the same as the Registration VLAN: If the 'Default VLAN' field in the switch port's model configuration is set to the same ID as the Registration VLAN, the port will not change state because FortiNAC-F believes it is already in its 'normal' or 'forced' state.

There is another unregistered host on the same port: FortiNAC-F maintains the security posture of the physical port. If multiple hosts are connected to a single port (e.g., via a hub or unmanaged switch) and at least one host remains 'Rogue' (unregistered), FortiNAC-F will generally keep the entire port in the isolation/registration VLAN to prevent the unregistered host from gaining unauthorized access to the production network.

Issues with agents (A, B) typically prevent a host from completing compliance or registration but do not usually result in a 'stuck' status after registration has already been marked as successful in the system.

'If a port is identified as having Multiple Hosts, and those hosts require different levels of access, FortiNAC remains in the most restrictive state (Registration or Isolation) until all hosts on that port are authorized... Additionally, verify the Default VLAN setting for the port; if the Default VLAN and Registration VLAN match, the system will not trigger a VLAN change upon registration.' --- FortiNAC-F Administration Guide: Troubleshooting Host Management.


Contribute your Thoughts:

0/2000 characters
Theron
5 days ago
I think I saw a similar question where the VLAN settings were key. Could C be a factor here?
upvoted 0 times
...
Santos
10 days ago
I remember something about agents being crucial for the registration process, so maybe options A or B could be the issue.
upvoted 0 times
...
Louisa
15 days ago
Alright, let me break this down. The host is registered but still in the registration VLAN, so it has to be an issue with the VLAN setup. I'm leaning towards C or D, but I'll double-check my understanding.
upvoted 0 times
...
Kent
20 days ago
Ugh, I'm so confused. I feel like I'm missing something obvious here. Maybe I should re-read the question and think it through step-by-step.
upvoted 0 times
...
Craig
25 days ago
I think I know this one! It's gotta be either C or D, since the host is staying in the registration VLAN after being registered.
upvoted 0 times
...
Corrie
1 month ago
Okay, let me see here. I'm pretty sure the answer has to do with the VLAN configuration, but I'm not sure which specific conditions would cause this.
upvoted 0 times
...
Erasmo
1 month ago
Hmm, this seems like a tricky one. I'll need to think through the different conditions carefully.
upvoted 0 times
...

Save Cancel