FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
krajaa
Staff
Staff
Article Id 194482

Description

 

This article describes why an SSL VPN MAC host check does not work in some FortiClients.

 

Scope

 

FortiClient.

Solution

 

An SSL VPN MAC Host Check Configuration does not work as expected in the following FortiClients:

 

  1. The free version of FortiClient 6.2 (Windows, Mac, and Linux) until FortiClient 7.0.2 does not support any type of host check. However, various host-checking features were re-added to the free version of FortiClient in 7.0.3 and onward, so an upgrade to this version or newer will help. See the new features section in the 7.0.0 documentation for more information.
  2. Mobile FortiClients (all versions of Android and iOS).
    For security reasons, Android & IOS will not allow Apps to be able to trace units and their users anymore. As a result, FortiClient will not be able to fetch the real MAC addresses of the mobile units. Consequently, the MAC check feature does not work in Mobile units.

 

Related article:

Technical Tip: FortiClient licensing and support **