Description | This article describes the expected behavior when MAC Address objects are used on SD-WAN rules. |
Scope | FortiOS 7.2.x. |
Solution |
Occasionally, there is a need to utilize MAC Address objects as sources or destinations in SD-WAN Rules. These objects can encompass multiple MAC Addresses, especially when devices possess multiple NICs. Nevertheless, when a MAC Address Object is set up with multiple MACs and used in an SD-WAN rule, it might not function correctly. This occurs because the fundamental concept of an SD-WAN rule is to map a specific device to a particular MAC Address and subsequently to a rule, not addresses in plurality. The observed behavior when employing MAC Address Objects within a rule containing multiple MAC Addresses could include the following:
For example:
Note that there exists a MAC Object labeled 'AUDI15_Wifi', encompassing 2 MAC Addresses. Additionally, this object is part of a group named 'MAC_ADDR_GROUP_1'. The inclusion of this object has been made within the SD-WAN Rule '1', titled TEST.
Upon inspecting the Rule Status via the CLI, only one MAC address is displayed, despite the object containing 2 MAC addresses. Consequently, if a device attempts network access using an NIC associated with the second MAC Address within the MAC Address Object, it will not trigger the rule. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.