FortiNAC Network Access Control
See every device on the network, and control what it can reach
Compare all 4 models
Figures are Fortinet’s own — sortable, cited on every product page| Model | Actions | |||
|---|---|---|---|---|
| FortiNAC CA-500FFNC-CA-500F | Mid-range control and application server | Small environments | Manages up to 5,000 ports in the network | Details |
| FortiNAC CA-600FFNC-CA-600F | High performance control and application server | Medium environments | Manages up to 15,000 ports in the network | Details |
| FortiNAC CA-700CFNC-CA-700C | Ultra high performance control and application server | Large environments with few persistent agents | Manages up to 25,000 ports in the network | Details |
| FortiNAC M-550FFNC-M-550F | Centralized management appliance | Multi-site deployments with multiple appliances | Manages up to 50 CA servers | Details |
How to read these numbers
FortiNAC answers a question most organisations cannot: what is actually connected. It discovers and profiles every device — including the unmanaged and unmanageable ones, cameras, badge readers, infusion pumps, PLCs — and then enforces what each is allowed to reach.
More on choosing within this range
It works agentlessly across multi-vendor infrastructure, so it covers the switches and wireless you already own rather than requiring a forklift. Enforcement is by dynamic VLAN assignment and ACLs pushed to the access layer.
Sizing is by ports in the network, and Fortinet is explicit that this means total switch ports plus maximum concurrent wireless connections — not the number of devices you think you have. The FNC-CA-500F covers up to 5,000 ports, the 600F up to 15,000, the 700C up to 25,000, and the FNC-M-550F is a management appliance for up to 50 control servers.
Before you order
How many ports, really?
Count every access-layer switch port plus your peak concurrent wireless client count. Under-sizing here is the most common FortiNAC purchasing error and it is not cheap to correct.
How many sites?
Multi-site deployments with several control servers need the FNC-M-550F management appliance on top of the control appliances. Single site does not.
Do you need persistent agents?
The 700C is specified for large environments with few persistent agents. If you plan heavy agent-based posture assessment, that changes the sizing — tell us the split.
What are you actually trying to fix?
If the goal is IoT and OT visibility, FortiNAC is the right tool. If it is user authentication for corporate laptops, 802.1X through FortiAuthenticator may be a much smaller project.
All FortiNAC Network Access Control
FortiNAC CA-500F
Mid-range control and application server — manages up to 5,000 ports in the network
FortiNAC CA-600F
High performance control and application server — manages up to 15,000 ports in the network
FortiNAC CA-700C
Ultra high performance control and application server — manages up to 25,000 ports in the network
FortiNAC M-550F
Centralized management appliance — manages up to 50 ca servers