Skip to main content
yoloknight
New Member
May 21, 2021
Question

MAC addressed-based policies via IPSec Tunnel

  • May 21, 2021
  • 1 reply
  • 1264 views

Hi Guys, I´m looking for a solution for IPv4 and IPv6 traffic via IPSec that only allows certain clients. (Interfaces are WLAN, LAN or LTE) The prefered soulution is that I can filter the clients with there MAC addresses. I tried it once with this guide: https://docs.fortinet.com/document/fortigate/6.2.0/new-features/485133/mac-address-based-policies But here I cant get a simple ping through the tunnel if I have address group with the mac. (i dont blacklist or something like that) What do I have to do to get this working? (for IPv4 and IPv6)

1 reply

bkrishnan
Staff
Staff
February 24, 2026

Please make sure that there is no L3 switch between the pc and the FortiGate, as it will change the source mac address and will not be possible to use a filter by mac address

Below article is for your reference:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Policy-filter-by-mac-address-not-working/ta-p/241005

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!