Created on 01-18-2016 07:10 AM Edited on 09-20-2023 01:21 PM By Anthony_E
Description
Solution
A MAC Address Access Control List (ACL) allows or blocks access on a network interface that includes a DHCP server.
A MAC Address ACL functions as either a list of blocked devices or a list of allowed devices. This is determined by the 'Unknown MAC Address' entry.
• By default, the ACL is a list of blocked devices. The 'Unknown MAC Address entry' Action is 'Assign IP'. Add an entry for each MAC address to block and set its Action to 'Block'.
• To have the ACL allow only a limited set of devices, set the 'Unknown MAC Address entry' to 'Block'. Then, add the MAC address of each allowed device. Set Action to 'Assign IP'.
Optionally, set Action to Reserve and enter the IP address that will always be assigned to the device.
To create a MAC Address ACL to allow only specific devices:
• Assign IP — device is assigned an IP address from the DHCP server address range.
• Reserve IP — device is assigned the IP address that you specify.
To create a MAC Address ACL to block specific devices:
Example:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.