Re: FortiOS 6.2 - removal of device groups - workaround/replacement?
Thanks for the reply. Yea I can see what they are trying to do, but for our scenario it is not a good approach. We have a lot of guests, visitors, maintenance guys, etc, who need to connect to the internet and I have set up 3 policies for internet access: completely blocked (except for software/av updates), default limited (allowing only business sites and social networks with 30 min quota) and admin access with everything allowed.
I have marked few devices in the construction area which are used by workers to have no internet access, office PCs and phones are using limited access and then few devices with admin access.Also any quest (non-marked devices) get limited access aswell.
Since it is a mix of LAN/Wifi access in different buildings it was easiest to set up this way. I know I could set this all up using VLANs and some kind of ACL on Wifi APs (most of them are not Forti APs), but it all adds to the complexity and is not that flexible, for example when moved from one place to another, or roaming between two different buildings and Wifi networks. I know this is less secure because anyone could theoretically change their MAC address to the one where net is allowed, but in our environment it is not likely to happen and I am ok with the risk.
Anyway I guess I will program a tool to convert currently set custom devices to MAC addresses and add them to the policy this way, and hopefully in the future they will change their mind.