| Description | This article describes why multiple VLANs in FortiGate can have the same MAC address, the reason behind the behavior, and limitations. |
| Scope | FortiGate. |
| Solution |
In FortiGate, multiple VLAN interfaces can share the same MAC address, especially when they are created under the same physical interface. By default, VLAN sub-interfaces inherit the MAC address of their parent interface and FortiGate does not assign unique MAC addresses to the VLAN interfaces bind to a specific interface.
Change of MAC address scope: In FortiGate, the MAC address of a VLAN interface cannot be manually changed. VLAN subinterfaces automatically assign the MAC address of their parent physical interface, and FortiGate does not provide an option to modify it.
In this case, if the same Mac address creates layer2 conflicts the following workarounds can be followed:
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.