NGAF issue

msj Lv1Posted 17 Jul 2024 14:57

Hi,
I have NGAF, and I want only domain devices should access the internet and if any unknown domain device or guest device connect to internal network should not access the internet.
Kindly suggest how to achieve that.

Product Name & Version No.: M4500-F-I & version 8.0.47

Thank You

Enrico Vanzetto has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Hi, you can achieve it by create a dedicated vlan on your netwrok environment for your domain users. You need to setup a radius server (you can look it for nps role on windows server) to allow the domain users to connect on this network. After that, on ngaf, you can allow only for this newly created vlan to go to internet without restrictions. About other networks (guest for example) you can create a dedicated vlan with ngaf as dhcp server and block internet access with a policy. This to achieve network isolation between domain clients and guest clients.
Is this answer helpful?
mdamores Lv3Posted 19 Jul 2024 21:43
  
Hi,
To make sure that only those domain devices are allowed and can access the internet while blocking unauthorized devices on your SAngfor NGAF, you may try following these steps:
1.        Ensure that your LAN and WAN are configured correctly
2.        Try assigning the appropriate interfaces to the LAN and WAN zones by going to Network > Interfaces > Zone
3.        Setup access control policies to allow internet access to those domain devices only by navigating to Policies > Access Control > Application Control and use domain ndevice identifiers like IP ranges or specifying MAC addresses
4.        Make sure that only domain devices can access the network by going to Policies > Device Compliance and create compliance policies and bind it to the domain devices using MAC address or unique identifiers
5.        To ensure that only authenticated domain users can access the intern, enable user authentication by going to Policies > User Authentication and configure authentication method to verify domain users
6.        Monitor the network traffic and adjust the policies as required

Imran Tahir Lv4Posted 19 Jul 2024 19:48
  
Go to polices and enabtle the authentication policy
msj Lv1Posted 18 Jul 2024 18:02
  
We already segregate all networks like management vlan 50, user vlan 10, server vlan 30 and guest 60. DHCP we configure on ngaf and SSO but due to logout issue and internet stop working once they connect back until they restart or logout/login  2-3 times. Currently I allowed whole network in policy instead of LDAP users. I will try domain isolation and other methods explain by other members. Most probably I will try next all these options.
Tayyab0101 Lv2Posted 18 Jul 2024 17:56
  
you need to create a dedicated vlan on your netwrok environment for your domain users only.
Farina Ahmed Lv5Posted 18 Jul 2024 17:46
  
For this, configure access control policies based on user authentication. Enable 802.1x authentication or integrate with your domain controller to enforce policies that only allow authenticated domain users to access the network. Any device not authenticated or recognized by the domain will be blocked from accessing the internet.
CLELUQMAN Lv3Posted 18 Jul 2024 09:17
  
you can set authentication policy .
Newbie290036 Lv4Posted 17 Jul 2024 20:15
  
To achieve this on your Sangfor NGAF M4500-F-I v8.0.47, you can configure the "Domain Isolation" feature. This feature allows you to isolate specific domains to the internet, while denying access to unknown or guest devices. To do this, go to the NGAF web interface, navigate to "Policy" > "Domain Isolation", and create a new policy. Select the domain(s) you want to isolate and set the "Outbound Access" to "Allow". Then, create a new rule with a "Source" of "Unknown" and set the "Action" to "Deny". This will block any unknown devices from accessing the internet. Finally, make sure to enable the policy and apply it to your desired zones or interfaces. This way, only authorized domain devices will be able to access the internet, while unknown or guest devices will be blocked.

I Can Help:

Change

Moderator on This Board

11
6
5

Started Topics

Followers

Follow

1
2
5

Started Topics

Followers

Follow

0
3
4

Started Topics

Followers

Follow

67
19
3

Started Topics

Followers

Follow

3
10
3

Started Topics

Followers

Follow

1
137
3

Started Topics

Followers

Follow

Board Leaders