Skip to main content
Palamar
New Member
September 10, 2015
Solved

how to block mac address?

  • September 10, 2015
  • 2 replies
  • 69312 views

I blocked user MAC Reservation + Access Control, but if the user sets himself a static IP address, it uses the Internet and network.How to fix?

Fortigate 80c

    Best answer by gschmitt

    You can block the internet access by creating a device and a policy to block the device

    Go to User&Devices > Device > Device Groups and Create New and create a "blockedMac" Group

    Go to User&Devices > Device > Device Definitions and select Create New (or look if it's already listed if you have Detect and Identify Devices on on the interface)

    Now go to Policy&Objects > Policy > IPv4 and Create new

    [ul]
  • Incoming Interface: Internal (or where the device is located)
  • Source Address: all (or your internal subnet)
  • Source Device Type: "BlockedMac"
  • Outgoing Interface: wan (your internet connection)
  • Service: All
  • Action: Deny[/ul]

     

    Repeat this if your servers are in a different subnet/interface for the interface

     

    Sadly your firewall cannot block internal traffic within the same subnet since the traffic literally does not cross the Fortigate

     

    If your FortiGate does DHCP you can go to System > Monitor > DHCP

    Look for the device in question and right click it and select Create/Edit IP Reservation

    Set the Action to Block

    But as you said the user can simply use a static IP

  • 2 replies

    rwpatterson
    New Member
    September 10, 2015

    The only way I know of is to set up a MAC reservation. If the user changes his IP address, then the reservation is broken and the traffic won't flow. I believe this is the behavior, but I may be wrong.

    gschmitt
    gschmittAnswer
    New Member
    September 11, 2015

    You can block the internet access by creating a device and a policy to block the device

    Go to User&Devices > Device > Device Groups and Create New and create a "blockedMac" Group

    Go to User&Devices > Device > Device Definitions and select Create New (or look if it's already listed if you have Detect and Identify Devices on on the interface)

    Now go to Policy&Objects > Policy > IPv4 and Create new

    [ul]
  • Incoming Interface: Internal (or where the device is located)
  • Source Address: all (or your internal subnet)
  • Source Device Type: "BlockedMac"
  • Outgoing Interface: wan (your internet connection)
  • Service: All
  • Action: Deny[/ul]

     

    Repeat this if your servers are in a different subnet/interface for the interface

     

    Sadly your firewall cannot block internal traffic within the same subnet since the traffic literally does not cross the Fortigate

     

    If your FortiGate does DHCP you can go to System > Monitor > DHCP

    Look for the device in question and right click it and select Create/Edit IP Reservation

    Set the Action to Block

    But as you said the user can simply use a static IP

  • Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!