Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
shcee0
New Contributor II

Why aren't Mac address based policies working normally?

Only pre-registered MAC addresses are allowed to communicate. The policy applies only to accounts and ip addresses and does not follow mac objects.

 

my rules:

1st. 

src : user1, 1.1.1.1, registered_mac_obj(ex. 11:11:11:11:11:11)      

dst : all

service : all

action : accept

 

2nd.

src : user1, 1.1.1.1, un_registered_mac_obj(00:00:00:00:00:00 ~ FF:FF:FF:FF:FF:FF)

dst : all

service : all

action : DENY

 

At this time, my PC's Mac address is 22:22:22:22:22:22 and belongs to un_registered_mac_obj,

but I still follow the first policy. The reason is unknown.

1 REPLY 1
srajeswaran
Staff
Staff

Can you test the behavior with a policy using only the mac address as match criteria and remove IP/user details (for testing).

 

ref: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-create-the-MAC-address-based-polici...

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Labels
Top Kudoed Authors