Question
source MAC address logging
The subject says it all. I manage multiple IDS/IPS installations from multiple vendors. Several of my clients expect me to be able to narrow down certain alerts to specific host systems. Nearly all of these client networks are DHCP environments, so IP addresses are pretty much useless. (Not that they are really that useful in a static environment either...) This should be quite easy for me to provide this information to the client. I have yet to find a way to have a FortiGate log the source MAC address for a specific alert. I realize this would have little use if the FG was placed in a routed environment... However, in a switched environment, this feature would be well worth having. Is this the " formal" location to request features? Or would it be better for me to open up a service ticket in the support website? Thanks,
