Description | This article describes an explanation of the 'use-interface-macs' parameter in FortiWeb's Virtual Zone (V-Zone) configuration and offers guidance on its usage. |
Scope | FortiWeb. |
Solution |
FortiWeb is a Web Application Firewall (WAF) designed to protect web applications from a variety of threats. In FortiWeb's configuration, the 'use-interface-macs' parameter under V-Zone settings plays a role in network traffic management and security. Understanding this parameter is essential for effective FortiWeb configuration.
Understanding the 'use-interface-macs' Parameter: The 'use-interface-macs' parameter is a setting within the V-Zone configuration in FortiWeb. This parameter controls whether FortiWeb uses the MAC (Media Access Control) addresses of its interfaces for V-Zone communication or if it uses the routing table for traffic forwarding.
Usage of the 'use-interface-macs' Parameter: Here is how to understand and use the 'use-interface-macs' parameter in FortiWeb V-Zone configuration:
When set to 'enable', FortiWeb will use the MAC addresses of its interfaces for V-Zone communication. This means that FortiWeb will use its interface MAC addresses to determine how to forward traffic between V-Zones.
This mode is generally suitable for scenarios where you have multiple V-Zones connected to different physical interfaces on FortiWeb, and one wants to ensure that traffic between these V-Zones is processed according to the interface-specific routing.
Configuration Example: Here is an example of how to configure the 'use-interface-macs' parameter in FortiWeb: config system v-zone
The 'use-interface-macs' parameter in FortiWeb's V-Zone configuration determines how FortiWeb manages traffic between Virtual Zones, whether by relying on the MAC addresses of its interfaces or by using the routing table. Understanding and configuring this parameter appropriately is essential for optimizing network traffic management and security in the FortiWeb deployment.
When configuring FortiWeb's V-Zones, consider the specific network requirements and topology to determine whether to enable or disable 'use-interface-macs' for each V-Zone. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.