Skip to main content
SPrabu
Staff
Staff
October 13, 2023

Technical Tip: FortiSwitch MAB Fake MAC address

  • October 13, 2023
  • 0 replies
  • 688 views
Description This article describes the fake MAC address seen in MAB authentication.
Scope FortiSwitch MAB.
Solution

Refer to the document for configuring FortiSwitch security policies:

FortiSwitch security policies

 

When the wired client (laptop or desktop) tries to connect to the switch port, it is possible to see a fake MAC address in the time frame of authentication.

 

  • The Fake MAC address will be 00:09:0f:xx:xx:xx (Fortinet vendor specific).
  • The Fake MAC is a place-hold MAC before it authenticates with the real MAC address of the wired client.
  • The MAC address will be seen only in the transition state of the MAB authentication and will disappear after authentication.

 

Example :

 

diagnose  switch  802-1x status port7

 

   Port7 : Mode: port-based (mac-by-pass enable)

           Link: Link up

           Port State: unauthorized: (  )

            EAP auto-untagged-vlans : Enable

           Dynamic Access Control List : Disable

           Native Vlan : 1

           Allowed Vlan list: 10,20,30

           Untagged Vlan list:

           Guest VLAN :

           Auth-Fail Vlan :

           AuthServer-Timeout Vlan :

           Sessions info:

           00:09:0f:xx:xx:xx    =========>  The fake MAC address.     Type=802.1x,,state=AUTHENTICATING,etime=0,eap_cnt=0 params:reAuth=0

               user="",security_grp="",fortinet_grp="" 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!