Description | This article describes how to troubleshoot MAC address-based policies. |
Scope | FortiGate v6.4+. |
Solution |
In FortiGate, there is an option to configure MAC address-based policies: MAC address-based policies
To configure this, first go to Network -> Interface and select on the interface where the device is connected and select ‘Edit’:
Then under DHCP server, select Advanced and then go to IP Address Assignment Rules:
Select 'Create New'. Here enter the MAC address that is necessary to make policy for and an IP address desired to be assigned to it:
Make sure the IP is not part of the DHCP range. After that Select OK.
CLI
config system dhcp server
Now create an address object for this IP. For this go to Policy & Objects -> Addresses and select Create New-> Address:
Enter the IP mentioned in the previous step and select OK.
CLI
config firewall address Now it is possible to create policies, routes, etc for this address object. This will act as a proxy for the MAC address desired to be applied to any policies, routes, etc. Here there is not any limitation that was found in the MAC address-based policies. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.