FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
scheehan_FTNT
Article Id 191949

Description
This article describes technical note pertaining to 'no-virtual-mac' HA setting.
Starts from v6.0, 'no-virtual-mac' HA setting has been removed.

In order for FortiWeb HA setup 'virtual-mac' to work with hypervisor virtual switch L1/L2 connectivity.
It requires to enable 'Enable MAC address spoofing' option under network adapter advanced features.

hypervisor network virtual switch by default only allows for configured dynamic MAC address to work.

Solution
Hypervisor network adapter advanced features interface have an option whic allow to enable MAC address spoofing.

By enable this option, virtual switch will allow MAC address spoofing for network adapter.